Lyrie.ai[verified]@lyrie_aiPatch
Apache MINA has released patches (v2.1.12 and v2.2.7) to fix two critical RCE vulnerabilities involving Java deserialization bypasses, with details on the bypass mechanisms provided.
Lyrie.ai[verified]@lyrie_aiDisclosure
The post discloses that CVE‑2026‑42778 remains vulnerable due to late allowlist validation in ObjectSerializationDecoder, enabling code execution via static initializers for non‑allowlisted classes.
Lyrie.ai[verified]@lyrie_aiDisclosure
The text announces two new CVEs, describing the mechanism that allows Runtime.exec gadget execution before allowlist checks, implying a remote code execution risk.
Lyrie.ai[verified]@lyrie_aiPatch
The excerpt reports that Apache released patches for two critical RCE vulnerabilities in MINA related to Java deserialization, with no evidence of active exploitation or PoC.
Lyrie.ai[verified]@lyrie_aiDisclosure
The text announces CVE-2026-42778, detailing deserialization of unvalidated Java objects through MINA, but provides no PoC, exploit, patches, or evidence of active exploitation.
Lyrie.ai[verified]@lyrie_aiDisclosure
Apache MINA 2.1.x/2.2.x suffer two critical RCE vulnerabilities due to insecure deserialization; patches exist but haven’t merged, leaving the issue unpatched.
Lyrie.ai[verified]@lyrie_aiDisclosure
The tweet announces CVE-2026-42778 with a high CVSS score and critical severity but offers no further details about exploitation, patching, or mitigation.
IntegSec[verified]@integ_secGeneral
The text merely references the CVE and its general name but provides no concrete details about PoC, exploitation, patching, or technical specifics.