As cited
Copy frozen at (site build).
vulnerabilities
NCSC-2026-0380 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Java SE
Oracle released patches for three high-severity vulnerabilities in Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition on September 16, 2026. Two vulnerabilities, CVE-2026-83357 and CVE-2026-83408, scored 8.1 on the CVSS scale and reside in the Compiler component, exploitable remotely without authentication or user interaction. Successful exploitation could lead to unauthorized access, data modification, and availability disruption.
Why it matters: Organizations running Oracle Java SE and GraalVM products should prioritize patching CVE-2026-83357 and CVE-2026-83408 immediately, as these allow remote code execution without authentication and could result in full system compromise.
- Source published
- First seen by Cybersecurity Tracker