PatchDay Alert

CVE

CVE-2026-41635

0field notes · 1digest CVSS 9.8


Daily digests

Another deserialization bypass in Apache MINA. The resolveClass() method has a code path for static classes and primitives that skips the allowlist entirely, letting an attacker sneak arbitrary classes past the filter and get remote code execution. This is a separate bypass from CVE-2026-41409, fixed in the same release. CVSS 9.8.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.