Apache MINA Hit by Twin Critical RCE Flaws
ID: 66f0a9df-50d6-5a7b-b96b-5ef56011cdfe
STIX ID: report--66f0a9df-50d6-5a7b-b96b-5ef56011cdfe
Feed Name: securityonline.info
Threat Score
Apache MINA has two critical deserialization vulnerabilities (CVE-2026-41635 and CVE-2026-41409) that enable remote code execution by either bypassing the classname allowlist in AbstractIoBuffer.resolveClass() or allowing static initializers to run before the allowlist is applied in AbstractIoBuffer.getObject(). The flaws affect multiple 2.0.x, 2.1.x, and 2.2.x releases and carry CVSS scores of 9.8; administrators are advised to upgrade immediately to 2.0.28, 2.1.11, or 2.2.6.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
