Oracle Java Se
53 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Oracle Java Se, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Oracle Java Se CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 5 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 1 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 3 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 7 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 3 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 5 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 9 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 18 |
| 2026-08 | 2 |
| 2026-09 | 0 |
Severity
How the 53 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High15
- Medium20
- Low18
Latest CVEs
The 15 most recently published vulnerabilities affecting Oracle Java Se.
- CVE-2026-71054Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 7u511. Easily exploitable vulnerability allows unauthenticated attacker with network acces...6.5
- CVE-2026-70906Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 25.0.4 and 26.0.2. Easily exploitable vulnerability allows unauthenticated attacker with ...7.5
- CVE-2026-62574Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Install). Supported versions that are affected are Oracle Java ...7.8
- CVE-2026-60526Vulnerability in Oracle Java SE (component: Installation). Supported versions that are affected are Oracle Java SE: 8u491 and 8u491-perf. Difficult to exploit vulnerability allows low privileged ...6.7
- CVE-2026-60166Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with netwo...3.1
- CVE-2026-60164Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with netwo...3.1
- CVE-2026-60147Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java...6.5
- CVE-2026-47063Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Jav...7.5
- CVE-2026-47057Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31. Easily exploitable vulnerability allows unauthentic...7.5
- CVE-2026-47059Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8...3.7
- CVE-2026-47058Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31. Difficult to exploit vulnerability allows unauthent...7.4
- CVE-2026-47034Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with netwo...3.1
- CVE-2026-47035Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with netwo...3.1
- CVE-2026-47027Vulnerability in Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JD...5.3
- CVE-2026-47030Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with netwo...3.1
Product grouping is registry-driven, with AI assist and human review. How it works