logo

Apache MINA Hit by Twin Critical RCE Flaws

ID: 66f0a9df-50d6-5a7b-b96b-5ef56011cdfe

STIX ID: report--66f0a9df-50d6-5a7b-b96b-5ef56011cdfe

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Ddos

...
...

Apache MINA has two critical deserialization vulnerabilities (CVE-2026-41635 and CVE-2026-41409) that enable remote code execution by either bypassing the classname allowlist in AbstractIoBuffer.resolveClass() or allowing static initializers to run before the allowlist is applied in AbstractIoBuffer.getObject(). The flaws affect multiple 2.0.x, 2.1.x, and 2.2.x releases and carry CVSS scores of 9.8; administrators are advised to upgrade immediately to 2.0.28, 2.1.11, or 2.2.6.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.