Lyrie.ai[verified]@lyrie_aiDisclosure
This post discloses CVE-2026-42778, noting that a previous patch for CVE‑2026‑41409 was incomplete, and explains that the allowlist validation flaw allows code execution via static initializers even for non‑allowlisted classes.
VulnTracker[verified]@vuln_trackerDisclosure
The post lists several high‑severity CVEs with exploitation details and CVSS scores, but provides no proof of active attacks, patches, or PoC code.
Kaitan ID Security[verified]@KaitanSecurityDisclosure
The post announces the critical CVE‑2026‑41409 with CVSS 9.8, highlights an incomplete fix for a related issue, notes no patch is yet available, and links to a detailed analysis.
Open Source Security mailing list@oss_securityDisclosure
Two new Apache MINA deserialization vulnerabilities, CVE‑2026‑41409 and CVE‑2026‑41635, have been disclosed with technical details and links to mailing‑list discussions.
CVE@CVEnewDisclosure
A new CVE-2026-41409 is reported as an incomplete fix to CVE-2024-52046 in Apache MINA, with no PoC, exploit code, patch, or detailed vulnerability information provided.
Vulmon Vulnerability Feed@VulmonFeedsGeneral
The tweet references CVE-2026-41409, noting an incomplete deserialization allowlist in Apache MINA and linking to vulnerability details, but does not provide exploit or mitigation information.