CVE-2026-41409Disclosure(apache / mina)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apache mina systems immediately
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: High priority (within 72h)

NVD description

The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in a class to be read might already have been executed. Affected versions are Apache MINA 2.0.0 <= 2.0.27, 2.1.0 <= 2.1.10, and 2.2.0 <= 2.2.5. The problem is resolved in Apache MINA 2.0.28, 2.1.11, and 2.2.6 by applying the classname allowlist earlier. Affected are applications using Apache MINA that call IoBuffer.getObject(). Applications using Apache MINA are advised to upgrade

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mina

Threat summary

  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-04-27); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
mina

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-04-27: 3Mentions · 2026-04-28: 2Mentions · 2026-06-04: 1Exploit Tool / Code · 2026-04-28: 1Patch / Workaround · 2026-06-04: 1Technical Details · 2026-04-27: 2Technical Details · 2026-04-28: 2Technical Details · 2026-06-04: 104-2704-2806-04
Signal classification2 categories
Disclosure
583.3%
General
116.7%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-273
Disclosure2General1
2026-04-282
Disclosure2
2026-06-041
Disclosure1
Full discourse6 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-41409: Apache MINA: CWE-502 Deserialization of Untrusted Data https://www.openwall.com/lists/oss-security/2026/04/27/3 ZDRES-059: CVE-2026-41635: Apache MINA: AbstractIoBuffer.resolveClass() null-clazz Branch Skips acceptMatchers Filter — Full Object Deserialization RCE https://www.openwall.com/lists/oss-security/2026/04/27/4

    Post summary

    Two new Apache MINA deserialization vulnerabilities, CVE‑2026‑41409 and CVE‑2026‑41635, have been disclosed with technical details and links to mailing‑list discussions.

    01040341
    4.7K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-42778 (Incomplete fix for CVE-2026-41409): The ObjectSerializationDecoder's allowlist validation fails when a class's static initializer is invoked — the check is applied too late, allowing payloads to execute code even for non-allowlisted classes.

    Post summary

    This post discloses CVE-2026-42778, noting that a previous patch for CVE‑2026‑41409 was incomplete, and explains that the allowlist validation flaw allows code execution via static initializers even for non‑allowlisted classes.

    1001033
    239 followersView on X
  • VulnTracker@vuln_tracker
    Disclosure

    Today's critical CVE highlights from our tracker: → Apache MINA: 2 unauthenticated RCE chains (CVE-2026-41409, 41635) → WordPress Directorist: privilege escalation + SQL injection → Totolink A8000RU: 16 (sixteen) RCEs in a single router model → ProjeQtor: unauth SQLi via login All CVSS 9.0+. All public exploits. https://vulntracker.io/digest

    Post summary

    The post lists several high‑severity CVEs with exploitation details and CVSS scores, but provides no proof of active attacks, patches, or PoC code.

    00010203
    605 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41409 The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too l… https://www.cve.org/CVERecord?id=CVE-2026-41409

    Post summary

    A new CVE-2026-41409 is reported as an incomplete fix to CVE-2024-52046 in Apache MINA, with no PoC, exploit code, patch, or detailed vulnerability information provided.

    00000122
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-41409 Incomplete Deserialization Allowlist in Apache MINA Abstr... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41409 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet references CVE-2026-41409, noting an incomplete deserialization allowlist in Apache MINA and linking to vulnerability details, but does not provide exploit or mitigation information.

    0000034
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-41409 The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of class… CVSS 9.8 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-41409 #Apache #CyberSecurity #InfoSec

    Post summary

    The post announces the critical CVE‑2026‑41409 with CVSS 9.8, highlights an incomplete fix for a related issue, notes no patch is yet available, and links to a detailed analysis.

    0000072
    142 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachemina---

Explore more