CVE-2026-94301

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed to the  2.2.X branch only. The 2.0.X and 2.1.X maintenance branches never received the resolveProxyClass() override, so the 2.0.29 and 2.1.13 artifacts listed as fixed -- and every later release on those lines, up to and including the current 2.0.30 and 2.1.14 -- remain vulnerable to the exact allow-list bypass that CVE-2026-47065 was meant to close.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 2 mentions (2026-09-21); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-09-21: 2Mentions · 2026-09-22: 209-2109-22
Referenced assets3 URLs
Full discourse4 posts
  • Upwind Security MDR@UpwindMDR

    🚨Critical - Apache MINA Java Proxy Allow-list Bypass Regression (CVE-2026-94301) Apache MINA 2.0.x/2.1.x missed the resolveProxyClass() override that was only applied in 2.2.x for CVE-2026-47065. Attackers can bypass the deserialization allow-list by leveraging java.lang.reflect.Proxy during class resolution, enabling gadget invocation and potential RCE. MINA 2.2.x is not affected. 👉Affected: Apache MINA 2.0.0-2.0.30, 2.1.0-2.1.14

    1001070
    304 followersView on X
  • Cybersecurity News DE@cybsecuritynews

    #schwachstellen Apache MINA: Kritische Lücke CVE-2026-94301 trifft 2.0.x und 2.1.x trotz früherer Korrektur #apachemina #cve202647065 #cve202694301 https://cybersecurity-news.de/apache-mina-cve-2026-94301-kritische-luecke-2-0-2-1

    000006
    12 followersView on X
  • SecAlerts@SecAlertsCo

    ⚠️ Apache MINA: the CVE-2026-47065 fix (acceptMatchers filter bypass via java.lang.reflect.Proxy) was never backported to 2.0.30 or 2.1.14. CVE-2026-94301, CVSS 9.8. Still on those branches? You're exposed. #cybersecurity #ciso #vulnerabilities https://secalerts.co/vulnerability/CVE-2026-94301?utm_campaign=x https://t.co/UVgY9i3RqU

    0000047
    888 followersView on X
  • Severity Daily@severitydaily

    Apache announced its 9.8 MINA deserialization fix as "Fully addressed" in three releases. It was committed to one branch. Two maintenance lines still listed as patched never received it. No exploitation reported. https://severitydaily.com/apache-mina-cve-2026-94301-resolveproxyclass-fix-2-2-branch-only/

    0000033
    24 followersView on X

Explore more