1 vulnerability across 1 product scored HIGH or above on September 21, 2026.
- ๐ HIGH: 1
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-93603 (patriksimek/vm2) โ F1: exploitable โ functional, AAS: 12.7 โ 14.7 (CRITICAL โ CRITICAL). Originally in 2026-09-18 bulletin.
- [UPGRADED] CVE-2026-93605 (patriksimek/vm2) โ F1: exploitable โ functional, AAS: 12.7 โ 14.7 (CRITICAL โ CRITICAL). Originally in 2026-09-18 bulletin.
- [UPGRADED] CVE-2026-84383 (strukturag/libheif) โ F1: exploitable โ functional, AAS: 10.9 โ 12.9 (HIGH โ CRITICAL). Originally in 2026-09-18 bulletin.
- [UPGRADED] CVE-2026-12793 (jetmonsters/jetformbuilder_โ_dynamic_blocks_form_builder) โ F1: exploitable โ functional, AAS: 10.1 โ 12.1 (HIGH โ CRITICAL). Originally in 2026-09-16 bulletin.
๐ [HIGH] apache_software_foundation/apache_mina
1 CVE | CVSS 3.1: 9.8 | AAS 9.9
cpe:2.3:a:apache:apache_mina:*:*:*:*:*:*:*:*(>= 2.0.0)cpe:2.3:a:apache:apache_mina:*:*:*:*:*:*:*:*(>= 2.1.0)cpe:2.3:a:apache:apache_mina:*:*:*:*:*:*:*:*(>= 2.2.0, < 2.2.8)
Apache MINA is affected by one critical vulnerability (CVE-2026-94301, CVSS 9.8) involving an incomplete fix for a previously disclosed deserialization filter bypass. The original patch for CVE-2026-47065, which addressed a proxy class resolution flaw allowing acceptMatchers filter bypass, was only applied to the 2.2.x branch despite being announced as fixed across all maintained release lines. As a result, MINA versions on the 2.0.x and 2.1.x branches, including the supposedly patched 2.0.29 and 2.1.13 releases and all subsequent versions up to 2.0.30 and 2.1.14, remain exploitable. Organizations using Apache MINA for network application development, particularly those relying on the 2.0.x or 2.1.x branches, should treat this as urgent. Review the vendor advisory at lists.apache.org for updated patch availability, and either migrate to the 2.2.x branch where the fix is present or apply the corrected patch for your branch as soon as it is released.
- ๐ CVE-2026-94301 (CVSS 3.1: 9.8)