TL;DR
The Apache Software Foundation resolved eight Apache MINA SSHD vulnerabilities. These critical security defects include authentication bypasses and server-side memory exhaustion flaws. Administrators must upgrade their Java applications to patched versions immediately to secure SSH connections.
- Total: 8 CVEs
- Severity: 3 Critical · 2 High · 3 Medium
- Actively exploited: None confirmed
- Highest severity: 9.1 (Critical · CVSSv3) — CVE-2026-94052
- Action: Apply the latest security updates now
See a Apache CVE's exploit risk spike before it becomes a headline.
Get EPSS spike alertsNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-94052 | 9.1 | CWE-304 | 2.20.0, 3.0.0-M6 | Not exploited |
| CVE-2026-94053 | 9.1 | CWE-90 | 2.20.0, 3.0.0-M6 | Not exploited |
| CVE-2026-77185 | 9.1 | CWE-305 | 2.20.0, 3.0.0-M6 | Not exploited |
| CVE-2026-93994 | 8.1 | CWE-304 | 2.20.0, 3.0.0-M6 | Not exploited |
| CVE-2026-94002 | 7.5 | CWE-770 | 2.20.0, 3.0.0-M6 | Not exploited |
| CVE-2026-94029 | 6.5 | CWE-770 | 2.20.0, 3.0.0-M6 | Not exploited |
| CVE-2026-93996 | 6.5 | CWE-770 | 2.20.0, 3.0.0-M6 | Not exploited |
| CVE-2026-93995 | 6.5 | CWE-20 | 2.20.0, 3.0.0-M6 | Not exploited |
Why It Matters
Thousands of enterprise Java applications deploy Apache MINA SSHD to provide secure communication channels. Consequently, critical Apache MINA SSHD vulnerabilities introduce substantial risk to backend infrastructure. The most severe defects carry critical CVSS scores of 9.1 and enable complete authentication bypasses. In addition, other flaws expose servers to severe memory exhaustion and denial of service conditions.
Currently, security teams have confirmed no active exploitation in the wild. Furthermore, researchers have not published any public proof-of-concept exploit code. However, unpatched servers remain exposed to unauthorized access and resource depletion. Therefore, resolving these Apache MINA SSHD vulnerabilities remains an urgent priority for enterprise developers.
How The Attack Works
The eight vulnerabilities target different modules within the library. Three critical flaws allow attackers to bypass authentication entirely. For instance, CVE-2026-94053 permits LDAP injection in the sshd-ldap component. An attacker uses wildcard characters to authenticate successfully without valid credentials. Similarly, CVE-2026-94052 involves a missing verification check in the LDAP password authenticator. Furthermore, CVE-2026-77185 enables an authentication bypass when developers implement custom asynchronous authentication logic.
Other flaws impact resource management. CVE-2026-94029 causes server-side memory exhaustion when an attacker requests a huge file with minimum block sizes via SFTP. The resulting massive reply buffers overwhelm server memory. Conversely, CVE-2026-94002 targets SFTP clients by flooding them with unsolicited replies. Additionally, CVE-2026-93996 allows peers to crash SCP handlers by sending endless command lines without line feeds. Finally, CVE-2026-93995 involves improper validation of archive commands in the sshd-git component. Separately, CVE-2026-93994 allows partial authentication bypasses by presenting the same public key twice.
Affected Versions
These defects impact multiple release branches of the library. The vulnerabilities affect Apache MINA SSHD versions up to 2.19.0. They also impact the 3.0.0 milestone releases from 3.0.0-M1 through 3.0.0-M5.
Patch Or Mitigation Steps
Development teams must update their project dependencies to secure versions immediately. The Apache Software Foundation resolved these issues in version 2.20.0 and version 3.0.0-M6. You can obtain the patched libraries directly from the Apache MINA SSHD downloads page. Applying these updates ensures secure authentication routing and prevents malicious memory exhaustion attacks.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!