BlackTreeCVE Intelligence
← Back to the CVE catalogue
Full vulnerability report · 2026
CVE-2026-34282High confidence

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking)

Oracle Corporation · Oracle Java SE

7.5HighCVSS 3.1
Recommended action
Within 7 days

High technical severity; prioritise exposed affected systems while verifying vendor guidance.

Patch available
R
Operational reassessment

Published severity in operational context

Open reassessment dashboard →
Published severityHighOperational priority:High, unchanged from published severity.unchanged

Evidence used

  • No CISA KEV confirmation is currently recorded.
  • The selected CVSS metric records a network-reachable, unauthenticated path with no user interaction.
  • EPSS is 0.89% for the current model date.

Compensating controls

  • Validate the affected product branch and deploy the verified fixed release.
  • Restrict the affected network interface to trusted sources where business-safe.
  • Monitor vendor guidance and exploitation sources for a material change.

Verification

  1. Confirm that the asset runs Oracle Corporation Oracle Java SE and falls inside the recorded affected range.
  2. Verify the installed build against the product-specific fixed version after deployment.
  3. Validate exposure, authentication requirements and compensating controls in the actual environment.
  4. Reopen this reassessment when CVSS, KEV, EPSS, exploit evidence or remediation changes.
Mitigation target: Within 30 daysRemediation target: Within 180 days

This automated reassessment organises public evidence. It does not know asset exposure, business impact or control effectiveness and does not replace CVSS or a human risk decision.

Distribution package intelligence

Release-specific package status

Alpine, Debian, ubuntu findings are scoped to the named distribution, release and source package. An absent finding does not mean a package is unaffected.

21 package states
Repository candidate not checked

A published vendor fix does not prove that a matching update is enabled and installable on a particular asset. Confirm the local package candidate before scheduling remediation.

Distribution releaseSource packageVendor stateFixed versionEvidence
Alpine v3.23v3.23 · communityopenjdk11Vendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.11.0.31_p11-r0Alpine Security Database ↗Source updated 11 Sep 2026
Alpine v3.23v3.23 · communityopenjdk17Vendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.17.0.19_p10-r0Alpine Security Database ↗Source updated 11 Sep 2026
Alpine v3.23v3.23 · communityopenjdk21Vendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.21.0.11_p10-r0Alpine Security Database ↗Source updated 11 Sep 2026
Alpine v3.23v3.23 · communityopenjdk25Vendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.25.0.3_p9-r0Alpine Security Database ↗Source updated 11 Sep 2026
Alpine v3.22v3.22 · communityopenjdk11Vendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.11.0.31_p11-r0Alpine Security Database ↗Source updated 11 Sep 2026
Alpine v3.22v3.22 · communityopenjdk17Vendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.17.0.19_p10-r0Alpine Security Database ↗Source updated 11 Sep 2026
Alpine v3.22v3.22 · communityopenjdk21Vendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.21.0.11_p10-r0Alpine Security Database ↗Source updated 11 Sep 2026
Debian trixietrixie · sourceopenjdk-21Vendor fix publishedDebian records a fixed source-package version for this release.21.0.11+10-1~deb13u2Debian Security Tracker ↗Source updated 6 Oct 2026
Debian trixietrixie · sourceopenjdk-25Vendor fix publishedDebian records a fixed source-package version for this release.25.0.3+9-2~deb13u1Debian Security Tracker ↗Source updated 6 Oct 2026
Debian bookwormbookworm · sourceopenjdk-17Vendor fix publishedDebian records a fixed source-package version for this release.17.0.19+10-1~deb12u2Debian Security Tracker ↗Source updated 6 Oct 2026
Debian forkyforky · sourceopenjdk-21Vendor fix publishedDebian records a fixed source-package version for this release.21.0.11+10-1Debian Security Tracker ↗Source updated 6 Oct 2026
Debian forkyforky · sourceopenjdk-25Vendor fix publishedDebian records a fixed source-package version for this release.25.0.3+9-1Debian Security Tracker ↗Source updated 6 Oct 2026
Debian sidsid · sourceopenjdk-11Vendor fix publishedDebian records a fixed source-package version for this release.11.0.31+11-1Debian Security Tracker ↗Source updated 6 Oct 2026
Debian sidsid · sourceopenjdk-17Vendor fix publishedDebian records a fixed source-package version for this release.17.0.19+10-1Debian Security Tracker ↗Source updated 6 Oct 2026
Debian sidsid · sourceopenjdk-21Vendor fix publishedDebian records a fixed source-package version for this release.21.0.11+10-1Debian Security Tracker ↗Source updated 6 Oct 2026
Debian sidsid · sourceopenjdk-25Vendor fix publishedDebian records a fixed source-package version for this release.25.0.3+9-1Debian Security Tracker ↗Source updated 6 Oct 2026
Ubuntu 24.04 LTSnoble · standard archiveopenjdk-17Vendor fix publishedCanonical reports that a fixed source package version has been published. Repository candidate availability is not checked by BlackTree.17.0.19+10-1~24.04.2Canonical Ubuntu Security ↗Source updated 5 Oct 2026
Ubuntu 24.04 LTSnoble · standard archiveopenjdk-21Vendor fix publishedCanonical reports that a fixed source package version has been published. Repository candidate availability is not checked by BlackTree.21.0.11+10-1~24.04.2Canonical Ubuntu Security ↗Source updated 5 Oct 2026
Ubuntu 24.04 LTSnoble · standard archiveopenjdk-25Vendor fix publishedCanonical reports that a fixed source package version has been published. Repository candidate availability is not checked by BlackTree.25.0.3+9-2~24.04.2Canonical Ubuntu Security ↗Source updated 5 Oct 2026
Ubuntu 24.04 LTSnoble · standard archiveopenjdk-8Vendor fix publishedCanonical reports that a fixed source package version has been published. Repository candidate availability is not checked by BlackTree.8u492-ga~us2-0ubuntu1~24.04.1Canonical Ubuntu Security ↗Source updated 5 Oct 2026
Ubuntu 24.04 LTSnoble · standard archiveopenjdk-ltsVendor fix publishedCanonical reports that a fixed source package version has been published. Repository candidate availability is not checked by BlackTree.11.0.31+11-1ubuntu1~24.04.2Canonical Ubuntu Security ↗Source updated 5 Oct 2026
Direct vendor intelligence

Authoritative vendor CSAF and VEX advisories

Structured product status and remediation from the issuing vendor. Product-state explanations are always visible; large lists can be searched or downloaded.

1 current
CVE-2026-34282 · CSAF 2.0 · revision 3 · finalRed Hat Product Securityopenjdk: Enhance TLS connection handling (Oracle CPU 2026-04)
39 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • java-1.6.0-openjdk as a component of Red Hat Enterprise Linux 6
  • java-1.6.0-openjdk-demo as a component of Red Hat Enterprise Linux 6
  • java-1.6.0-openjdk-devel as a component of Red Hat Enterprise Linux 6
  • java-1.6.0-openjdk-javadoc as a component of Red Hat Enterprise Linux 6
  • java-1.6.0-openjdk-src as a component of Red Hat Enterprise Linux 6
  • java-1.6.0-openjdk.src as a component of Red Hat Enterprise Linux 6
  • java-1.7.0-openjdk as a component of Red Hat Enterprise Linux 6
  • java-1.7.0-openjdk-demo as a component of Red Hat Enterprise Linux 6
  • java-1.7.0-openjdk-devel as a component of Red Hat Enterprise Linux 6
  • java-1.7.0-openjdk-javadoc as a component of Red Hat Enterprise Linux 6
  • java-1.7.0-openjdk-src as a component of Red Hat Enterprise Linux 6
  • java-1.7.0-openjdk.src as a component of Red Hat Enterprise Linux 6
Summary
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26; Oracle GraalVM for JDK: 17.0.18 and 21.0.10; Oracle GraalVM Enterprise Edition: 21.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
Optional official sources

National CERT insights
?CERT means Computer Emergency Response Team; CSIRT is the closely related term Computer Security Incident Response Team.

Choose official national sources for this report. Each advisory shows its original language. Your selection is remembered on this device and included in shared links.

Official European source

ENISA European Vulnerability Database

Official EUVD identifiers, advisory evidence and known-exploited context. Missing fields are not treated as evidence of low risk.

1 current
ENISA EUVD identifier

EUVD-2026-24362

No EUVD known-exploited evidence

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26; Oracle GraalVM for JDK: 17.0.18 and 21.0.10; Oracle GraalVM Enterprise Edition: 21.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

EUVD state
Present in the current official mapping
Known exploitation
Not present in the current ENISA EUVD known-exploited dataset. This is not proof of no exploitation.
ENISA score
7.5 · CVSS 3.1
Advisory evidence
No linked advisory details stored yet
Recommended actionWithin 7 days

High technical severity; prioritise exposed affected systems while verifying vendor guidance.

Patch available
01

What, why and how

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26; Oracle GraalVM for JDK: 17.0.18 and 21.0.10; Oracle GraalVM Enterprise Edition: 21.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

What

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26; Oracle GraalVM for JDK: 17.0.18 and 21.0.10; Oracle GraalVM Enterprise Edition: 21.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

Why

The product does not properly control the allocation and maintenance of a limited resource.

How

An attacker operating through a network path may attempt exploitation without authentication or user interaction. If successful, the issue may disrupt the affected service.

What

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26; Oracle GraalVM for JDK: 17.0.18 and 21.0.10; Oracle GraalVM Enterprise Edition: 21.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

Why

The product does not properly control the allocation and maintenance of a limited resource.

How

An attacker operating through a network path may attempt exploitation without authentication or user interaction. If successful, the issue may disrupt the affected service.

02

Exploit reality and attack path

CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.

Observed exploitation
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
No confirmed evidence

No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.

Public PoC / exploit material
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
None recorded

No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.

Likely attack path
a network path → Uncontrolled Resource Consumption → disrupt the affected service
Attack surface
Network
Privileges required
None: unauthenticated exploitation is possible
User interaction
None
Attack complexity
Low: no specialised conditions are recorded
Security boundary
Unchanged: impact remains within the vulnerable component's security authority
Weakness
?CWE means Common Weakness Enumeration: a standard category for the underlying weakness.
CWE-400 ↗

CWE-400: Uncontrolled Resource Consumption. The product does not properly control the allocation and maintenance of a limited resource.

CVSS vector
?CVSS means Common Vulnerability Scoring System. The vector records the metric values used to calculate technical severity.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Common Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.

AVNetworkAttack vector: The vulnerable component can be reached over a network.ACLowAttack complexity: No specialised conditions are required beyond attacker-controlled input.PRNonePrivileges required: The attacker does not need an account or existing privileges.UINoneUser interaction: No action by another user is required.SUnchangedScope: The security impact remains within the vulnerable component's authority.CNoneConfidentiality impact: No direct loss is represented by this metric.INoneIntegrity impact: No direct loss is represented by this metric.AHighAvailability impact: A successful attack can cause a major loss.
Post-exploitation / living off the land
No specific living-off-the-land technique is confirmed in the structured sources. Monitor normal administration tools for activity inconsistent with the affected service's baseline.
NetworkUnauthenticatedDenial of serviceCWE-400
A

Official authority intelligence

Only matched European and national findings are included. Language selectors and unavailable sources are omitted.

ENISA EUVD · EUVD-2026-24362Official EUVD mapping

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26; Oracle GraalVM for JDK: 17.0.18 and 21.0.10; Oracle GraalVM Enterprise Edition: 21.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

Official EUVD record ↗
BSI · German · WID-SEC-2026-1687IBM License Metric Tool: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM License Metric Tool ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.

Official advisory ↗
BSI · German · WID-SEC-2026-1201Oracle Java SE: Mehrere Schwachstellen

Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Java SE ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory ↗
Cyber Security Agency of Singapore · English · CSA-SB-20260422Security Bulletin 22 April 2026

The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 22 April 2026, published on 22 April 2026. Open the linked bulletin for the product, severity and reference information published in that issue.

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-1206Multiples vulnérabilités dans les produits IBM

d?id=CVE-2026-30922 Référence CVE CVE-2026-31958 https://www.cve.org/CVERecord?id=CVE-2026-31958 Référence CVE CVE-2026-33230 https://www.cve.org/CVERecord?id=CVE-2026-33230 Référence CVE CVE-2026-33231 https://www.cve.org/CVERecord?id=CVE-2026-33231 Référence CVE CVE-2026-33236 https://www.cve.org/CVERecord?id=CVE-2026-33236 Référence CVE CVE-2026-33416 https://www.cve.org/CVERecord?id=CVE-2026-33416 Référence CVE CVE-2026-34073 https://www.cve.org/CVERecord?id=CVE-2026-34073 Référence CVE CVE-2026-34197 https://www.cve.org/CVERecord?id=CVE-2026-34197 Référence CVE CVE-2026-34268 https://www.cve.org/CVERecord?id=CVE-2026-34268 Référence CVE CVE-2026-34282 https://www.cve.org/CVERecord?id=CVE-2026-34282 Référence CVE CVE-2026-34477 https://www.cve.org/CVERecord?id=CVE-2026-34477 Référence CVE CVE-2026-34478 https://www.cve.org/CVERecord?id=CVE-2026-34478 Référence CVE CVE-2026-34479 https://www.cve.org/CVERecord?id=CVE-2026-34479 Référence CVE CVE-2026-34480 https://www.cve.org/CVERecord?id=CVE-2026-34480 Référence CVE CVE-2026-34481 https://www.cve.org/CVERecord?id=CVE-2026-34481 Référence CVE CVE-2026-35536 https://www.cve.org/CVERecord?id=CVE-2026-35536 Référence CVE CVE-2026-3621 https://www.cve.org/CVERecord?id=CVE-2026-3621 Référence CVE CVE-2026-3713 https://www.cve.org/CVERecord?id=CVE

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-1121Multiples vulnérabilités dans les produits IBM

d?id=CVE-2026-22008 Référence CVE CVE-2026-22013 https://www.cve.org/CVERecord?id=CVE-2026-22013 Référence CVE CVE-2026-22016 https://www.cve.org/CVERecord?id=CVE-2026-22016 Référence CVE CVE-2026-22018 https://www.cve.org/CVERecord?id=CVE-2026-22018 Référence CVE CVE-2026-22021 https://www.cve.org/CVERecord?id=CVE-2026-22021 Référence CVE CVE-2026-23865 https://www.cve.org/CVERecord?id=CVE-2026-23865 Référence CVE CVE-2026-24733 https://www.cve.org/CVERecord?id=CVE-2026-24733 Référence CVE CVE-2026-24734 https://www.cve.org/CVERecord?id=CVE-2026-24734 Référence CVE CVE-2026-34268 https://www.cve.org/CVERecord?id=CVE-2026-34268 Référence CVE CVE-2026-34282 https://www.cve.org/CVERecord?id=CVE-2026-34282 Référence CVE CVE-2026-34477 https://www.cve.org/CVERecord?id=CVE-2026-34477 Référence CVE CVE-2026-34478 https://www.cve.org/CVERecord?id=CVE-2026-34478 Référence CVE CVE-2026-34479 https://www.cve.org/CVERecord?id=CVE-2026-34479 Référence CVE CVE-2026-34480 https://www.cve.org/CVERecord?id=CVE-2026-34480 Référence CVE CVE-2026-34481 https://www.cve.org/CVERecord?id=CVE-2026-34481 Référence CVE CVE-2026-41254 https://www.cve.org/CVERecord?id=CVE-2026-41254 Référence CVE CVE-2026-46917 https://www.cve.org/CVERecord?id=CVE-2026-46917 Référence CVE CVE-2026-46968 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-1094Multiples vulnérabilités dans les produits IBM

d?id=CVE-2026-33558 Référence CVE CVE-2026-33671 https://www.cve.org/CVERecord?id=CVE-2026-33671 Référence CVE CVE-2026-33672 https://www.cve.org/CVERecord?id=CVE-2026-33672 Référence CVE CVE-2026-33750 https://www.cve.org/CVERecord?id=CVE-2026-33750 Référence CVE CVE-2026-33845 https://www.cve.org/CVERecord?id=CVE-2026-33845 Référence CVE CVE-2026-33846 https://www.cve.org/CVERecord?id=CVE-2026-33846 Référence CVE CVE-2026-34043 https://www.cve.org/CVERecord?id=CVE-2026-34043 Référence CVE CVE-2026-34197 https://www.cve.org/CVERecord?id=CVE-2026-34197 Référence CVE CVE-2026-34268 https://www.cve.org/CVERecord?id=CVE-2026-34268 Référence CVE CVE-2026-34282 https://www.cve.org/CVERecord?id=CVE-2026-34282 Référence CVE CVE-2026-34481 https://www.cve.org/CVERecord?id=CVE-2026-34481 Référence CVE CVE-2026-34513 https://www.cve.org/CVERecord?id=CVE-2026-34513 Référence CVE CVE-2026-34514 https://www.cve.org/CVERecord?id=CVE-2026-34514 Référence CVE CVE-2026-34515 https://www.cve.org/CVERecord?id=CVE-2026-34515 Référence CVE CVE-2026-34516 https://www.cve.org/CVERecord?id=CVE-2026-34516 Référence CVE CVE-2026-34517 https://www.cve.org/CVERecord?id=CVE-2026-34517 Référence CVE CVE-2026-34518 https://www.cve.org/CVERecord?id=CVE-2026-34518 Référence CVE CVE-2026-34519 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-0901Multiples vulnérabilités dans les produits IBM

d?id=CVE-2026-33227 Référence CVE CVE-2026-33532 https://www.cve.org/CVERecord?id=CVE-2026-33532 Référence CVE CVE-2026-33671 https://www.cve.org/CVERecord?id=CVE-2026-33671 Référence CVE CVE-2026-33672 https://www.cve.org/CVERecord?id=CVE-2026-33672 Référence CVE CVE-2026-33750 https://www.cve.org/CVERecord?id=CVE-2026-33750 Référence CVE CVE-2026-33814 https://www.cve.org/CVERecord?id=CVE-2026-33814 Référence CVE CVE-2026-34043 https://www.cve.org/CVERecord?id=CVE-2026-34043 Référence CVE CVE-2026-34077 https://www.cve.org/CVERecord?id=CVE-2026-34077 Référence CVE CVE-2026-34268 https://www.cve.org/CVERecord?id=CVE-2026-34268 Référence CVE CVE-2026-34282 https://www.cve.org/CVERecord?id=CVE-2026-34282 Référence CVE CVE-2026-34479 https://www.cve.org/CVERecord?id=CVE-2026-34479 Référence CVE CVE-2026-3449 https://www.cve.org/CVERecord?id=CVE-2026-3449 Référence CVE CVE-2026-3520 https://www.cve.org/CVERecord?id=CVE-2026-3520 Référence CVE CVE-2026-35536 https://www.cve.org/CVERecord?id=CVE-2026-35536 Référence CVE CVE-2026-39304 https://www.cve.org/CVERecord?id=CVE-2026-39304 Référence CVE CVE-2026-39821 https://www.cve.org/CVERecord?id=CVE-2026-39821 Référence CVE CVE-2026-39827 https://www.cve.org/CVERecord?id=CVE-2026-39827 Référence CVE CVE-2026-39828 https://www.cve.org/CVERecord?id=CVE-

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-0810Multiples vulnérabilités dans les produits IBM

rd?id=CVE-2026-2332 Référence CVE CVE-2026-23865 https://www.cve.org/CVERecord?id=CVE-2026-23865 Référence CVE CVE-2026-25680 https://www.cve.org/CVERecord?id=CVE-2026-25680 Référence CVE CVE-2026-25681 https://www.cve.org/CVERecord?id=CVE-2026-25681 Référence CVE CVE-2026-27136 https://www.cve.org/CVERecord?id=CVE-2026-27136 Référence CVE CVE-2026-33814 https://www.cve.org/CVERecord?id=CVE-2026-33814 Référence CVE CVE-2026-33870 https://www.cve.org/CVERecord?id=CVE-2026-33870 Référence CVE CVE-2026-33871 https://www.cve.org/CVERecord?id=CVE-2026-33871 Référence CVE CVE-2026-34268 https://www.cve.org/CVERecord?id=CVE-2026-34268 Référence CVE CVE-2026-34282 https://www.cve.org/CVERecord?id=CVE-2026-34282 Référence CVE CVE-2026-34477 https://www.cve.org/CVERecord?id=CVE-2026-34477 Référence CVE CVE-2026-34478 https://www.cve.org/CVERecord?id=CVE-2026-34478 Référence CVE CVE-2026-34479 https://www.cve.org/CVERecord?id=CVE-2026-34479 Référence CVE CVE-2026-34480 https://www.cve.org/CVERecord?id=CVE-2026-34480 Référence CVE CVE-2026-39821 https://www.cve.org/CVERecord?id=CVE-2026-39821 Référence CVE CVE-2026-40175 https://www.cve.org/CVERecord?id=CVE-2026-40175 Référence CVE CVE-2026-40895 https://www.cve.org/CVERecord?id=CVE-2026-40895 Référence CVE CVE-2026-42033 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-0788Multiples vulnérabilités dans les produits IBM

d?id=CVE-2026-27903 Référence CVE CVE-2026-27904 https://www.cve.org/CVERecord?id=CVE-2026-27904 Référence CVE CVE-2026-29181 https://www.cve.org/CVERecord?id=CVE-2026-29181 Référence CVE CVE-2026-32635 https://www.cve.org/CVERecord?id=CVE-2026-32635 Référence CVE CVE-2026-33671 https://www.cve.org/CVERecord?id=CVE-2026-33671 Référence CVE CVE-2026-33672 https://www.cve.org/CVERecord?id=CVE-2026-33672 Référence CVE CVE-2026-33750 https://www.cve.org/CVERecord?id=CVE-2026-33750 Référence CVE CVE-2026-33814 https://www.cve.org/CVERecord?id=CVE-2026-33814 Référence CVE CVE-2026-34268 https://www.cve.org/CVERecord?id=CVE-2026-34268 Référence CVE CVE-2026-34282 https://www.cve.org/CVERecord?id=CVE-2026-34282 Référence CVE CVE-2026-39821 https://www.cve.org/CVERecord?id=CVE-2026-39821 Référence CVE CVE-2026-39824 https://www.cve.org/CVERecord?id=CVE-2026-39824 Référence CVE CVE-2026-40355 https://www.cve.org/CVERecord?id=CVE-2026-40355 Référence CVE CVE-2026-40356 https://www.cve.org/CVERecord?id=CVE-2026-40356 Référence CVE CVE-2026-40973 https://www.cve.org/CVERecord?id=CVE-2026-40973 Référence CVE CVE-2026-40975 https://www.cve.org/CVERecord?id=CVE-2026-40975 Référence CVE CVE-2026-40977 https://www.cve.org/CVERecord?id=CVE-2026-40977 Référence CVE CVE-2026-41035 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-0667Multiples vulnérabilités dans les produits IBM

d?id=CVE-2026-33412 Référence CVE CVE-2026-33916 https://www.cve.org/CVERecord?id=CVE-2026-33916 Référence CVE CVE-2026-33937 https://www.cve.org/CVERecord?id=CVE-2026-33937 Référence CVE CVE-2026-33938 https://www.cve.org/CVERecord?id=CVE-2026-33938 Référence CVE CVE-2026-33939 https://www.cve.org/CVERecord?id=CVE-2026-33939 Référence CVE CVE-2026-33940 https://www.cve.org/CVERecord?id=CVE-2026-33940 Référence CVE CVE-2026-33941 https://www.cve.org/CVERecord?id=CVE-2026-33941 Référence CVE CVE-2026-34197 https://www.cve.org/CVERecord?id=CVE-2026-34197 Référence CVE CVE-2026-34268 https://www.cve.org/CVERecord?id=CVE-2026-34268 Référence CVE CVE-2026-34282 https://www.cve.org/CVERecord?id=CVE-2026-34282 Référence CVE CVE-2026-34601 https://www.cve.org/CVERecord?id=CVE-2026-34601 Référence CVE CVE-2026-34982 https://www.cve.org/CVERecord?id=CVE-2026-34982 Référence CVE CVE-2026-35213 https://www.cve.org/CVERecord?id=CVE-2026-35213 Référence CVE CVE-2026-35385 https://www.cve.org/CVERecord?id=CVE-2026-35385 Référence CVE CVE-2026-35386 https://www.cve.org/CVERecord?id=CVE-2026-35386 Référence CVE CVE-2026-35387 https://www.cve.org/CVERecord?id=CVE-2026-35387 Référence CVE CVE-2026-35388 https://www.cve.org/CVERecord?id=CVE-2026-35388 Référence CVE CVE-2026-35414 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-0641Multiples vulnérabilités dans les produits IBM

d?id=CVE-2026-31958 Référence CVE CVE-2026-32141 https://www.cve.org/CVERecord?id=CVE-2026-32141 Référence CVE CVE-2026-32597 https://www.cve.org/CVERecord?id=CVE-2026-32597 Référence CVE CVE-2026-33186 https://www.cve.org/CVERecord?id=CVE-2026-33186 Référence CVE CVE-2026-33228 https://www.cve.org/CVERecord?id=CVE-2026-33228 Référence CVE CVE-2026-33671 https://www.cve.org/CVERecord?id=CVE-2026-33671 Référence CVE CVE-2026-33672 https://www.cve.org/CVERecord?id=CVE-2026-33672 Référence CVE CVE-2026-33750 https://www.cve.org/CVERecord?id=CVE-2026-33750 Référence CVE CVE-2026-34268 https://www.cve.org/CVERecord?id=CVE-2026-34268 Référence CVE CVE-2026-34282 https://www.cve.org/CVERecord?id=CVE-2026-34282 Référence CVE CVE-2026-35554 https://www.cve.org/CVERecord?id=CVE-2026-35554 Référence CVE CVE-2026-35611 https://www.cve.org/CVERecord?id=CVE-2026-35611 Référence CVE CVE-2026-3713 https://www.cve.org/CVERecord?id=CVE-2026-3713 Référence CVE CVE-2026-40175 https://www.cve.org/CVERecord?id=CVE-2026-40175 Référence CVE CVE-2026-41676 https://www.cve.org/CVERecord?id=CVE-2026-41676 Référence CVE CVE-2026-41677 https://www.cve.org/CVERecord?id=CVE-2026-41677 Référence CVE CVE-2026-41678 https://www.cve.org/CVERecord?id=CVE-2026-41678 Référence CVE CVE-2026-41681 https://www.cve.org/CVERecord?id=CV

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-0468Multiples vulnérabilités dans Oracle Java SE

De multiples vulnérabilités ont été découvertes dans Oracle Java SE. Elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2026-013042オラクルのOracle GraalVM等の複数製品におけるリソースの枯渇に関する脆弱性

Oracle Java SE、Oracle GraalVM for JDK、Oracle GraalVM Enterprise Edition製品のOracle Java SE(コンポーネント:Networking)における脆弱性です。影響を受けるサポート対象バージョンは、Oracle Java SE:8u481-perf、11.0.30、17.0.18、21.0.10、25.0.2、26;Oracle GraalVM for JDK:17.0.18および21.0.10;Oracle GraalVM Enterprise Edition:21.3.17です。複数のプロトコルを介したネットワークアクセスを持つ認証されていない攻撃者により、容易に悪用可能な脆弱性であり、Oracle Java SE、Oracle GraalVM for JDK、Oracle GraalVM Enterprise Editionが侵害される可能性があります。この脆弱性の攻撃が成功すると、Oracle Java SE、Oracle GraalVM for JDK、Oracle GraalVM Enterprise Editionがハングしたり、頻繁に繰り返されるクラッシュ(完全なDoS)を不正に引き起こすことが可能となります。注:この脆弱性は、指定されたコンポーネントのAPIを使用して悪用可能であり、例えばAPIにデータを提供するWebサービスを通じて利用されることがあります。また、この脆弱性は、Javaサンドボックスをセキュリティのために利用し、インターネットから取得したコードなど信頼できないコードをロードし実行するサンドボックス化されたJava Web StartアプリケーションやJavaアプレットを実行しているクライアントに対するJava展開にも該当します。CVSS 3.1基本スコア7.5(可用性に影響)です。CVSSベクターは(CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)です。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2026-016983Cosminexusにおける複数の脆弱性

Cosminexus Developer's Kit for Java(TM),および,Hitachi Developer's Kit for Javaに下記の脆弱性が存在します。 CVE-2026-22007, CVE-2026-22013, CVE-2026-22016, CVE-2026-22018, CVE-2026-22021, CVE-2026-23865, CVE-2026-34268, CVE-2026-34282

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2026-016982Hitachi Command Suite製品, Hitachi Automation Director, Hitachi Configuration Manager, Hitachi Infrastructure Analytics AdvisorおよびHitachi Ops Center製品における複数の脆弱性

Hitachi Command Suite製品, Hitachi Automation Director, Hitachi Configuration Manager, Hitachi Infrastructure Analytics AdvisorおよびHitachi Ops Center製品に複数の脆弱性が存在します。 CVE-2026-22007, CVE-2026-22013, CVE-2026-22016, CVE-2026-22018, CVE-2026-22021, CVE-2026-23865, CVE-2026-34268, CVE-2026-34282

Official advisory ↗
03

Patch and workaround

Operational remediation based on structured source evidence.

Status
?Patch availability is based on structured fixed-version fields and authoritative update references. If no fix is verified, check the vendor advisory before making a change.
Patch available
Affected
Fixed
Action
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
Workaround
No verified workaround is recorded. If business-safe, reduce exposure to the affected interface and allow only trusted sources until authoritative guidance is available.
04

Evidence and provenance

Published 21 Apr 2026 · Last source change 18 Sept 2026, 12:04 UTC · CWE-400 · Uncontrolled Resource Consumption

CVE recordCVE.org · 5.2
CVSS sourceCNA
EPSS source
?The date BlackTree first stored a score for this CVE from the daily FIRST EPSS feed.
FIRST · tracked since 2026-08-14
European sourceENISA EUVD · EUVD-2026-24362
Product sourceVendor CSAF · Red Hat Product Security
Remediation sourceVendor CSAF · Red Hat Product Security
CWE sourceCISA ADP
NVD statusNVD modified after enrichment

Core structured fields are present and their contributing authorities are shown above.

Material change intelligence

What changed after publication

View recent updates ↗
  1. Affected versionsThe structured affected or fixed version information changed.
    Before
    java-1.6.0-openjdk as a component of Red Hat Enterprise Linux 6; java-1.6.0-openjdk-demo as a component of Red Hat Enterprise Linux 6; java-1.6.0-openjdk-devel as a component of Red Hat Enterprise Linux 6; java-1.6.0-openjdk-javadoc as a component of Red Hat Enterprise Linux 6; java-1.6.0-openjdk-src as a component of Red Hat Enterprise Linux 6; java-1.6.0-openjdk.src as a component of Red Hat Enterprise Linux 6; java-1.7.0-openjdk as a component of Red Hat Enterprise Linux 6; java-1.7.0-openjdk-demo as a component of Red Hat Enterprise Linux 6; java-1.7.0-openjdk-devel as a component of Red Hat Enterprise Linux 6; java-1.7.0-openjdk-javadoc as a component of Red Hat Enterprise Linux 6; java-1.7.0-openjdk-src as a component of Red Hat Enterprise Linux 6; java-1.7.0-openjdk.src as a component of Red Hat Enterprise Linux 6; java-1.8.0-openjdk as a component of Red Hat Enterprise Linux 6; java-1.8.0-openjdk-debug as a component of Red Hat Enterprise Linux 6; java-1.8.0-openjdk-demo as a component of Red Hat Enterprise Linux 6; java-1.8.0-openjdk-demo-debug as a component of Red Hat Enterprise Linux 6; java-1.8.0-openjdk-devel as a component of Red Hat Enterprise Linux 6; java-1.8.0-openjdk-devel-debug as a component of Red Hat Enterprise Linux 6; java-1.8.0-openjdk-headless as a component of Red Hat Enterprise Linux 6; java-1.8.0-openjdk-headless-debug as a component of Red Hat Enterprise Linux 6; java-1.8.0-openjdk-javadoc as a component of Red Hat Enterprise Linux 6; java-1.8.0-openjdk-javadoc-debug as a component of Red Hat Enterprise Linux 6; java-1.8.0-openjdk-src as a component of Red Hat Enterprise Linux 6; java-1.8.0-openjdk-src-debug as a component of Red Hat Enterprise Linux 6; java-1.8.0-openjdk.src as a component of Red Hat Enterprise Linux 6; java-1.6.0-openjdk as a component of Red Hat Enterprise Linux 7; java-1.6.0-openjdk-demo as a component of Red Hat Enterprise Linux 7; java-1.6.0-openjdk-devel as a component of Red Hat Enterprise Linux 7; java-1.6.0-openjdk-javadoc as a component of Red Hat Enterprise Linux 7; java-1.6.0-openjdk-src as a component of Red Hat Enterprise Linux 7; and 9 more · Fixed: java-11-openjdk-1:11.0.31.0.11-1.el7_9.s390x as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-1:11.0.31.0.11-1.el7_9.src as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-1:11.0.31.0.11-1.el7_9.x86_64 as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-debug-1:11.0.31.0.11-1.el7_9.s390x as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-debug-1:11.0.31.0.11-1.el7_9.x86_64 as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-debuginfo-1:11.0.31.0.11-1.el7_9.s390x as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-debuginfo-1:11.0.31.0.11-1.el7_9.x86_64 as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-demo-1:11.0.31.0.11-1.el7_9.s390x as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-demo-1:11.0.31.0.11-1.el7_9.x86_64 as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-demo-debug-1:11.0.31.0.11-1.el7_9.s390x as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-demo-debug-1:11.0.31.0.11-1.el7_9.x86_64 as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-devel-1:11.0.31.0.11-1.el7_9.s390x as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-devel-1:11.0.31.0.11-1.el7_9.x86_64 as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-devel-debug-1:11.0.31.0.11-1.el7_9.s390x as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-devel-debug-1:11.0.31.0.11-1.el7_9.x86_64 as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-headless-1:11.0.31.0.11-1.el7_9.s390x as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-headless-1:11.0.31.0.11-1.el7_9.x86_64 as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-headless-debug-1:11.0.31.0.11-1.el7_9.s390x as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-headless-debug-1:11.0.31.0.11-1.el7_9.x86_64 as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-javadoc-1:11.0.31.0.11-1.el7_9.s390x as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-javadoc-1:11.0.31.0.11-1.el7_9.x86_64 as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-javadoc-debug-1:11.0.31.0.11-1.el7_9.s390x as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-javadoc-debug-1:11.0.31.0.11-1.el7_9.x86_64 as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-javadoc-zip-1:11.0.31.0.11-1.el7_9.s390x as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-javadoc-zip-1:11.0.31.0.11-1.el7_9.x86_64 as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-javadoc-zip-debug-1:11.0.31.0.11-1.el7_9.s390x as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-javadoc-zip-debug-1:11.0.31.0.11-1.el7_9.x86_64 as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-jmods-1:11.0.31.0.11-1.el7_9.s390x as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-jmods-1:11.0.31.0.11-1.el7_9.x86_64 as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-jmods-debug-1:11.0.31.0.11-1.el7_9.s390x as a component of Red Hat OpenJDK 11 ELS for RHEL 7; and 2385 more
    After
    java-1.6.0-openjdk as a component of Red Hat Enterprise Linux 6; java-1.6.0-openjdk-demo as a component of Red Hat Enterprise Linux 6; java-1.6.0-openjdk-devel as a component of Red Hat Enterprise Linux 6; java-1.6.0-openjdk-javadoc as a component of Red Hat Enterprise Linux 6; java-1.6.0-openjdk-src as a component of Red Hat Enterprise Linux 6; java-1.6.0-openjdk.src as a component of Red Hat Enterprise Linux 6; java-1.7.0-openjdk as a component of Red Hat Enterprise Linux 6; java-1.7.0-openjdk-demo as a component of Red Hat Enterprise Linux 6; java-1.7.0-openjdk-devel as a component of Red Hat Enterprise Linux 6; java-1.7.0-openjdk-javadoc as a component of Red Hat Enterprise Linux 6; java-1.7.0-openjdk-src as a component of Red Hat Enterprise Linux 6; java-1.7.0-openjdk.src as a component of Red Hat Enterprise Linux 6; java-1.8.0-openjdk as a component of Red Hat Enterprise Linux 6; java-1.8.0-openjdk-debug as a component of Red Hat Enterprise Linux 6; java-1.8.0-openjdk-demo as a component of Red Hat Enterprise Linux 6; java-1.8.0-openjdk-demo-debug as a component of Red Hat Enterprise Linux 6; java-1.8.0-openjdk-devel as a component of Red Hat Enterprise Linux 6; java-1.8.0-openjdk-devel-debug as a component of Red Hat Enterprise Linux 6; java-1.8.0-openjdk-headless as a component of Red Hat Enterprise Linux 6; java-1.8.0-openjdk-headless-debug as a component of Red Hat Enterprise Linux 6; java-1.8.0-openjdk-javadoc as a component of Red Hat Enterprise Linux 6; java-1.8.0-openjdk-javadoc-debug as a component of Red Hat Enterprise Linux 6; java-1.8.0-openjdk-src as a component of Red Hat Enterprise Linux 6; java-1.8.0-openjdk-src-debug as a component of Red Hat Enterprise Linux 6; java-1.8.0-openjdk.src as a component of Red Hat Enterprise Linux 6; java-1.6.0-openjdk as a component of Red Hat Enterprise Linux 7; java-1.6.0-openjdk-demo as a component of Red Hat Enterprise Linux 7; java-1.6.0-openjdk-devel as a component of Red Hat Enterprise Linux 7; java-1.6.0-openjdk-javadoc as a component of Red Hat Enterprise Linux 7; java-1.6.0-openjdk-src as a component of Red Hat Enterprise Linux 7; and 9 more · Fixed: java-11-openjdk-1:11.0.31.0.11-1.el7_9.s390x as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-1:11.0.31.0.11-1.el7_9.src as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-1:11.0.31.0.11-1.el7_9.x86_64 as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-debug-1:11.0.31.0.11-1.el7_9.s390x as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-debug-1:11.0.31.0.11-1.el7_9.x86_64 as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-debuginfo-1:11.0.31.0.11-1.el7_9.s390x as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-debuginfo-1:11.0.31.0.11-1.el7_9.x86_64 as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-demo-1:11.0.31.0.11-1.el7_9.s390x as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-demo-1:11.0.31.0.11-1.el7_9.x86_64 as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-demo-debug-1:11.0.31.0.11-1.el7_9.s390x as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-demo-debug-1:11.0.31.0.11-1.el7_9.x86_64 as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-devel-1:11.0.31.0.11-1.el7_9.s390x as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-devel-1:11.0.31.0.11-1.el7_9.x86_64 as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-devel-debug-1:11.0.31.0.11-1.el7_9.s390x as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-devel-debug-1:11.0.31.0.11-1.el7_9.x86_64 as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-headless-1:11.0.31.0.11-1.el7_9.s390x as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-headless-1:11.0.31.0.11-1.el7_9.x86_64 as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-headless-debug-1:11.0.31.0.11-1.el7_9.s390x as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-headless-debug-1:11.0.31.0.11-1.el7_9.x86_64 as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-javadoc-1:11.0.31.0.11-1.el7_9.s390x as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-javadoc-1:11.0.31.0.11-1.el7_9.x86_64 as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-javadoc-debug-1:11.0.31.0.11-1.el7_9.s390x as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-javadoc-debug-1:11.0.31.0.11-1.el7_9.x86_64 as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-javadoc-zip-1:11.0.31.0.11-1.el7_9.s390x as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-javadoc-zip-1:11.0.31.0.11-1.el7_9.x86_64 as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-javadoc-zip-debug-1:11.0.31.0.11-1.el7_9.s390x as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-javadoc-zip-debug-1:11.0.31.0.11-1.el7_9.x86_64 as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-jmods-1:11.0.31.0.11-1.el7_9.s390x as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-jmods-1:11.0.31.0.11-1.el7_9.x86_64 as a component of Red Hat OpenJDK 11 ELS for RHEL 7; java-11-openjdk-jmods-debug-1:11.0.31.0.11-1.el7_9.s390x as a component of Red Hat OpenJDK 11 ELS for RHEL 7; and 2384 more
    Red Hat Product Security ↗
  2. Vendor guidanceAuthoritative vendor guidance changed: added remediation: oracle.com/cpuapr2026.html.
    Before
    vendor advisory: oracle.com/cpuapr2026.html
    After
    remediation: oracle.com/cpuapr2026.html · vendor advisory: oracle.com/cpuapr2026.html
    secalert_us@oracle.com ↗
  3. Affected versionsThe structured affected or fixed version information changed.
    Before
    8u481-perf; 11.0.30; 17.0.18; 21.0.10; 25.0.2; 26; 21.3.17 · Fixed: No fixed version is explicitly recorded in the structured CVE data.
    After
    Oracle Java SE: 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26; Oracle GraalVM for JDK: 17.0.18, 21.0.10; Oracle GraalVM Enterprise Edition: 21.3.17 · Fixed: RHSA-2026:9254: Red Hat OpenJDK 11 ELS for RHEL 7, Red Hat OpenJDK 11 ELS for RHEL 8, Red Hat OpenJDK 11 ELS for RHEL 9
    CNA ↗
  4. Remediation statusRemediation status changed from Awaiting fix to Patch available.
    Before
    Awaiting fix
    After
    Patch available
    secalert_us@oracle.com ↗
Material fields only · duplicate refreshes suppressed · history retained for the configured operational retention period
Technical terms and abbreviations used in this report
CVE
Common Vulnerabilities and Exposures: the public identifier for one disclosed vulnerability.
CVSS
Common Vulnerability Scoring System: a technical severity framework; it is not patching priority by itself.
EPSS
Exploit Prediction Scoring System: FIRST's estimate of the probability that exploitation activity will be observed in the next 30 days; it is a forecast, not confirmation.
CWE
Common Weakness Enumeration: the standard category describing the underlying software or hardware weakness.
CNA
CVE Numbering Authority: an organisation authorised to assign and publish CVE records.
CISA ADP
Cybersecurity and Infrastructure Security Agency Authorized Data Publisher: structured enrichment added to a CVE record.
NVD
National Vulnerability Database: NIST's enrichment service for CVE records.
CERT / CSIRT
A computer security incident response team that publishes warnings or coordinates incident response.
PoC
Proof of concept: public material that demonstrates or helps reproduce exploitation.
CSAF
Common Security Advisory Framework: a machine-readable format for security advisories.
LoTL
Living off the land: abuse of legitimate tools or system functions during an attack.
Free version - for non-commercial use only.CVE-2026-34282 · cve.blacktree.nl