CYBERSECURITYTRACKER
TRACKING6,877 stories in this site build1,441 vulnerability news stories in this site build
Permanent story citation

NCSC-2026-0380 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Java SE

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7520

As cited

Copy frozen at (site build).

vulnerabilities

NCSC-2026-0380 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Java SE

Oracle released patches for three high-severity vulnerabilities in Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition on September 16, 2026. Two vulnerabilities, CVE-2026-83357 and CVE-2026-83408, scored 8.1 on the CVSS scale and reside in the Compiler component, exploitable remotely without authentication or user interaction. Successful exploitation could lead to unauthorized access, data modification, and availability disruption.

Why it matters: Organizations running Oracle Java SE and GraalVM products should prioritize patching CVE-2026-83357 and CVE-2026-83408 immediately, as these allow remote code execution without authentication and could result in full system compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary