CVE-2026-42779Disclosure(apache / mina)

HIGHCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 7 mentions and remains active

Immediate actions

  • Patch apache mina systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at all, bypassing the classname allowlist and allowing arbitrary code to be executed. The fix checks if the class is present in the accepted class filter before calling Class.forName(). Affected versions are Apache MINA 2.1.0 <= 2.1.11, and 2.2.0 <= 2.2.6. The problem is resolved in Apache MINA 2.1.12, and 2.2.7 by applying the classname allowlist earlier. Affected are applications using Apache MINA that call IoBuffer.getObject(). Applications using Apache MINA are advised to upgrade.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mina

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 29 mentions across 14 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 23 signals
  • Disclosure: 15 classified signals
  • General: 4 classified signals
  • Peaked 3d ago at 7 mentions (2026-06-13); latest day: 1
  • 29 total mentions across 14 days

Affected systems

Vendors
Products
mina

Deep dive

Activity timeline29 mentions / 14d
02457Mentions · 2026-05-01: 3Mentions · 2026-05-02: 3Mentions · 2026-05-06: 1Mentions · 2026-05-11: 1Mentions · 2026-05-13: 2Mentions · 2026-06-01: 2Mentions · 2026-06-04: 2Mentions · 2026-06-05: 2Mentions · 2026-06-10: 1Mentions · 2026-06-11: 2Mentions · 2026-06-13: 7Mentions · 2026-07-04: 1Mentions · 2026-07-21: 1Mentions · 2026-09-25: 1PoC Mentioned / Linked · 2026-05-02: 2PoC Mentioned / Linked · 2026-05-06: 1PoC Mentioned / Linked · 2026-06-11: 1PoC Mentioned / Linked · 2026-07-04: 1Exploit Tool / Code · 2026-07-04: 1Active Exploitation · 2026-06-05: 2Patch / Workaround · 2026-05-01: 1Patch / Workaround · 2026-05-02: 1Patch / Workaround · 2026-06-01: 1Patch / Workaround · 2026-06-04: 1Patch / Workaround · 2026-06-05: 2Patch / Workaround · 2026-06-11: 1Patch / Workaround · 2026-06-13: 1Technical Details · 2026-05-01: 3Technical Details · 2026-05-02: 3Technical Details · 2026-05-06: 1Technical Details · 2026-05-11: 1Technical Details · 2026-05-13: 1Technical Details · 2026-06-01: 2Technical Details · 2026-06-04: 2Technical Details · 2026-06-05: 1Technical Details · 2026-06-10: 1Technical Details · 2026-06-11: 2Technical Details · 2026-06-13: 4Technical Details · 2026-07-04: 1Technical Details · 2026-09-25: 105-0105-0205-0605-1105-1306-0106-0406-0506-1006-1106-1307-0407-2109-25
Signal classification5 categories
Disclosure
1551.7%
Patch
517.2%
General
413.8%
PoC
310.3%
Active Exploitation
26.9%
Referenced assets23 URLs
Classification over time
DateTotalLabels
2026-05-013
Disclosure3
2026-05-023
Disclosure1Patch1PoC1
2026-05-061
PoC1
2026-05-111
Disclosure1
2026-05-132
General2
2026-06-012
Disclosure2
2026-06-042
Disclosure1Patch1
2026-06-052
Active Exploitation2
2026-06-101
Disclosure1
2026-06-112
Disclosure1Patch1
2026-06-137
Disclosure4General1Patch2
2026-07-041
PoC1
2026-07-211
General1
2026-09-251
Disclosure1
Full discourse20 posts
  • Nicolas Krassas@Dinosn
    Disclosure

    CVE-2026-42779: Apache MINA AbstractIoBuffer.resolveClass() deserialization filter bypass to RCE (CVSS 9.8) https://github.com/dinosn/CVE-2026-42779

    Post summary

    Apache MINA’s CVE-2026-42779 reveals a deserialization bypass leading to RCE (CVSS 9.8), and a GitHub link suggests a PoC is available.

    024077366.9K
    158.1K followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    CVE-2026-42779: Apache MINA-Deserialization Allowlist Bypass to RCE https://blog.securelayer7.net/cve-2026-42779-apache-mina-deserialization-rce/

    Post summary

    The text references CVE-2026-42779, a deserialization bug in Apache MINA that can lead to remote code execution, and points to a blog article for further details.

    110651.3K
    158.9K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    Sources Apache MINA CVE-2026-42779: The Patch That Wasn't Spring Boot CVE-2026-40976: Active Exploitation Post-Patch CISA 72-Hour Patch Deadline Proposal: Why Speed Became the Enemy M-Trends 2026: The 22-Second Hand-Off Window That Broke Patching

    Post summary

    The text lists sources indicating active exploitation of Spring Boot CVE‑2026‑40976 and discussing patch status for Apache MINA CVE‑2026‑42779, but it does not provide technical details or PoC information.

    1101159
    246 followersView on X
  • ET Labs@ET_Labs
    Disclosure

    6 new OPEN, 7 new PRO (6 + 1) CVE-2026-17633 (IBM Langflow RCE), CVE-2026-87902 (Wordpress Core Template Path Traversal), CVE-2026-42779 (Apache MINA Allowlist Bypass RCE), TA569, and more. https://community.emergingthreats.net/t/ruleset-update-summary-2026-09-25-v11298/3464

    Post summary

    The post announces three new CVEs (IBM Langflow RCE, WordPress Core Template Path Traversal, Apache MINA Allowlist Bypass RCE) as part of a ruleset update, providing their vulnerability types but no PoC, exploit, patch, or active exploitation details.

    02001273
    5.7K followersView on X
  • Mr. OS@ksg93rd
    PoC

    #Analytics #Threat_Research An analytical review of the main cybersecurity events (June 27 - July 04, 2026) 1⃣. Bad Epoll (CVE-2026-46242) https://github.com/J-jaeyoung/bad-epoll // race-condition UaF in the Linux kernel's epoll subsystem 2⃣. Mitigated API authentication bypass for python*org download metadata https://blog.python.org/2026/06/mitigated-api-bypass-for-download-metadata-python-dot-org 3⃣. Exploits for 23 unpatched vulnerabilities in FFmpeg, VLC, Firefox, Docker, PHP, OpenVPN, nmap, libssh2, nghttp2, and 7zip have been disclosed https://github.com/bikini/exploitarium 4⃣. Beware of the license manager: how a Schneider Electric software vulnerability puts industrial facilities at risk https://securelist.com/tr/schneider-electric-cve-2024-2658-vulnerability/120436 5⃣. Apple Hide My Email Vulnerability https://www.404media.co/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses 6⃣. DNS Tricks to Load Malware into Cloned Repository https://0din.ai/blog/clone-this-repo-and-i-own-your-machine 7⃣. Google Gemini CLI Vulnerability https://github.com/advisories/GHSA-jj69-4grx-fqj5 // CVE-2026-12537 8⃣. Apache MINA Deserialization Bypass to RCE https://blog.securelayer7.net/cve-2026-42779-apache-mina-deserialization-rce // CVE-2026-42779 affects Apache MINA versions 2.1.0 - 2.1.11 and 2.2.0 - 2.2.6 9. CyberPocket makes cybersecurity alerts easy to understand. Paste an alert, upload a screenshot, or submit a security message, and CyberPocket turns confusing technical details into a clear summary, risk level, next steps, and client-ready ticket notes. Built for individuals, students, IT teams, MSPs, MSSPs, and SOC analysts, CyberPocket helps you triage faster, learn smarter, and respond with confidence. Visit http://cyberpocket.org and turn confusing alerts into clear action. 10. Build smarter AI agents faster. http://www.GenieBot.Store helps you generate production-ready AI agent system prompts for Claude, ChatGPT, OpenAI, Gemini, Mistral, Llama, and custom LLMs. Choose your tier, describe your business, select your platform, and receive a customized prompt built to help your AI agent think, respond, and operate with purpose.

    Post summary

    The review enumerates several new CVEs, linking to PoC repositories and providing technical details, but does not report active exploitation, patch availability, or disproof of the vulnerabilities.

    00021407
    3.4K followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    TL;DR Apache MINA 2.1.12 and 2.2.7 patch two critical RCE flaws (CVE-2026-42778, CVE-2026-42779) that escaped previous security releases. Both vulnerabilities involve Java deserialization bypasses — one via static initializers, the other via type-checking gaps — allowing…

    Post summary

    Apache MINA issued patch versions 2.1.12 and 2.2.7 to fix CVE-2026-42778 and CVE-2026-42779, which involve Java deserialization bypasses. No active exploitation or exploit code is disclosed.

    2001039
    239 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Critical - Apache MINA Deserialization RCE (CVE-2026-42779 | CVSS 9.8) A flaw in AbstractIoBuffer.resolveClass() bypasses the classname allowlist during object deserialization via IoBuffer.getObject() - no validation on specific code paths. 👉 No auth required → full remote code execution on the server | Upgrade to 2.1.12 or 2.2.7 immediately

    Post summary

    The post announces a critical RCE CVE‑2026‑42779 in Apache MINA, explains how the allowlist bypass works, and urges operators to patch to 2.1.12 or 2.2.7.

    00030146
    237 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    CVE-2026-42779 · 9.8 → 2.1.0 Apache MINA — the foundational Java network framework powering everything from enterprise SSH gateways to IoT protocol handlers — has spent the last eighteen months issuing patches that don't fully close the hole they claim to.

    Post summary

    Patch updates for CVE-2026-42779 appear insufficient to fully close the vulnerability, according to the analysis.

    1000048
    267 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The Patch That Wasn't: Apache MINA CVE-2026-42779 Deserialization Bypass Proves the Incomplete-Fix Pattern Still Kills On May 1, 2026, security researchers disclosed CVE-2026-42779 in Apache MINA, a critical Java networking framework used across enterprise messaging…

    Post summary

    The article announces the discovery of CVE‑2026‑42779, a deserialization bypass in Apache MINA, highlighting concerns about an incomplete patch.

    1000031
    267 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    In CVE-2026-42779, the vulnerable branch never validates the class before calling Class.forName(), effectively bypassing the entire classname allowlist.

    Post summary

    The text reveals that CVE-2026-42779 bypasses the classname allowlist by skipping class validation before Class.forName(), providing a key technical detail about the vulnerability.

    1000014
    267 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    The Patch That Wasn''t: Apache MINA CVE-2026-42779 Deserialization Bypass Proves the Incomplete-Fix Pattern Still Kills. The Patch That Wasn't: Apache MINA CVE-2026-42779 Deserialization Bypass Proves the Incomplete-Fix Pattern Still Kills

    Post summary

    The headline highlights an incomplete patch for Apache MINA CVE‑2026‑42779, showing that a deserialization bypass remains exploitable.

    1000026
    267 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    On May 1, 2026, security researchers disclosed CVE-2026-42779 in Apache MINA, a critical Java networking framework used across enterprise messaging systems, IoT platforms, and distributed applications. The vulnerability is a re-emergence of an older flaw (CVE-2026-41635)…

    Post summary

    Security researchers disclose CVE‑2026‑42779 in Apache MINA, identifying it as a re‑emergence of an older flaw (CVE‑2026‑41635). The announcement does not include proof‑of‑concept, exploit code, or patch details.

    1000023
    267 followersView on X
  • ✪ 𝕱𝖆𝖍𝖆𝖉@fad_777
    Patch

    ثغرة قد تفتح الباب لتنفيذ أوامر عن بعد. ثغرة CVE 2026 42779 تؤثر على Apache MINA عبر تجاوز قائمة السماح أثناء إلغاء التسلسل، ما يبرز أهمية مراجعة التعرض وتطبيق التحديثات بسرعة. Deserialization controls can become an RCE path. CVE 2026 42779 highlights an allowlist bypass in Apache MINA, turning unsafe deserialization into a potential remote code execution risk. Review exposure and patch guidance. https://blog.securelayer7.net/cve-2026-42779-apache-mina-deserialization-rce/ #ApacheMINA #Deserialization #RCE

    Post summary

    CVE‑2026‑42779 is a deserialization flaw in Apache MINA that allows an attacker to bypass an allowlist and achieve remote code execution; patch guidance is provided in the linked blog.

    0001086
    75 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    3. The "Invisible Patch" Problem Not all patches actually work. In April 2026 alone, we saw: Apache MINA CVE-2026-42779: "Patched" deserialization flaw that still had a bypass Spring Boot CVE-2026-40976: "Fixed" auth flaw that attackers exploited 72 hours after patch…

    Post summary

    The post highlights that two recent patches were ineffective, as attackers exploited the flaws within hours, underscoring the need for rigorous validation of fixes.

    1000057
    246 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    However: CVE-2026-42778: Static initializers of disallowed classes execute before the allowlist check, allowing gadgets like Runtime.exec() to fire even on rejected types. CVE-2026-42779: Primitive types (int, byte, etc.) and static class references (e.g., String.class)…

    Post summary

    The snippet announces two new CVEs with technical details on how static initializers bypass allowlist checks and enable gadget execution.

    1000033
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    TL;DR Apache MINA 2.1.x and 2.2.x contain two critical remote code execution vulnerabilities (CVE-2026-42778 and CVE-2026-42779) stemming from insecure deserialization. The patches were written months ago but failed to merge into two release branches due to repository…

    Post summary

    Apache MINA 2.1.x and 2.2.x contain two critical RCE vulnerabilities (CVE-2026-42778 & CVE-2026-42779) caused by insecure deserialization; patches existed months earlier but were not merged into the release branches.

    1000062
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-42779: Logic-Flaw RCE in AbstractIoBuffer.resolveClass() This is the more critical flaw. A specific programming branch in the AbstractIoBuffer.resolveClass() method omits the acceptMatchers security filter that would normally prevent dangerous classes from being…

    Post summary

    The post discloses CVE‑2026‑42779 as a logic‑flaw remote code execution issue in AbstractIoBuffer.resolveClass() due to a missing security filter.

    1000046
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-42779 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post simply lists CVE-2026-42779 as a CRITICAL advisory with CVSS details, providing no additional context on exploitation, patches, or mitigations.

    1000037
    210 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-42779: Apache MINA Deserialization Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04q9jJS0

    Post summary

    The excerpt identifies CVE-2026-42779 as an Apache MINA deserialization flaw but offers no further detail on exploitation, fixes, or PoC.

    0000031
    32 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    https://lyrie.ai/research/research/apache-mina-deserialization-trilogy-cve-2026-42779-allowlist-bypass #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The link points to a research post announcing a new Apache MINA deserialization vulnerability (CVE‑2026‑42779) that bypasses allowlists, but no evidence of exploitation, patches, or PoC code is provided.

    0000017
    267 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachemina---

Explore more