SECURITYONLINE [.]info reports that eight vulnerabilities in Apache MINA SSHD were patched in a recent update. The flaws span authentication bypasses and resource-management issues, with the most severe defects rated at CVSS v3 scores of 9.1. The highest-severity CVEs include CVE-2026-94052, CVE-2026-94053 and CVE-2026-77185, which respectively enable an LDAP-related authentication bypass or allow bypasses via custom authentication logic.
The remaining flaws—CVE-2026-93994, CVE-2026-94002, CVE-2026-94029, CVE-2026-93996 and CVE-2026-93995—primarily affect memory handling, server responses, or command validation in various MINA SSHD components and can lead to memory exhaustion, denial of service, or partial authentication bypasses.
The affected software spans Apache MINA SSHD versions up to 2.19.0 and the 3.0.0 milestone stream (from 3.0.0-M1 through 3.0.0-M5). The patching comes in versions 2.20.0 and 3.0.0-M6, with the guidance to apply these updates immediately from the Apache MINA SSHD downloads page. At present, the report notes no confirmed exploitation in the wild, though unpatched systems remain at risk of unauthorized access or resource depletion.
Administrators are urged to update promptly to secure authentication paths and mitigate memory-related attack vectors. The article lists the eight CVEs with their fixed versions and notes that none are marked as exploited at the time of publication on 1 October 2026.