Upwind Security MDR[verified]@UpwindMDRPatch
The post alerts users to a critical deserialization flaw in Apache MINA that can lead to RCE and recommends upgrading to patched versions.
Lyrie.ai[verified]@lyrie_aiDisclosure
Researchers disclosed CVE-2026-42779, a critical vulnerability in Apache MINA that re‑emerges from an earlier flaw, without providing PoC, exploitation, or patch details.
Kaitan ID Security[verified]@KaitanSecurityPatch
The tweet alerts to a critical CVE‑2026‑42779 with a CVSS score of 9.8, notes that no patch has been released, and links to a detailed analysis.
Kaitan ID Security[verified]@KaitanSecurityDisclosure
The tweet announces a critical vulnerability (CVE-2026-41635) in Apache MINA, providing brief technical details and a CVSS score, but does not indicate an available PoC, exploit, or active exploitation.
Gray Hats@the_yellow_fallPatch
The post highlights a critical RCE flaw in Apache MINA (CVE-2026-41635), provides technical details about a deserialization filter bypass, and directs readers to a patch guide for remediation.
Open Source Security mailing list@oss_securityDisclosure
The message announces two new Apache MINA vulnerabilities—one involving deserialization of untrusted data (CWE‑502) and another enabling full object deserialization RCE—without providing PoC, exploit code, or patch information.
CCB Alert@CCBalertPatch
The advisory warns of a critical arbitrary code execution flaw in Apache MINA (CVE‑2026‑41635) with a CVSS score of 9.8 and urges users to apply the patch immediately.
CVE@CVEnewDisclosure
The CVE involves a class‑check bypass in Apache MINA's AbstractIoBuffer.resolveClass, potentially enabling arbitrary class loading; no PoC, exploit, or mitigation is disclosed.