Vulnerability in Oracle Java SE Affecting JavaFX Component
CVE-2026-60166

3.1LOW

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60166?

A security vulnerability in Oracle Java SE, specifically in the JavaFX component, allows unauthenticated attackers with network access to exploit it through various protocols. This vulnerability, present in the supported version Oracle Java SE: 8u491, necessitates human interaction for successful exploitation, which could lead to unauthorized read access to certain accessible data. This primarily affects Java deployments in environments running sandboxed Java Web Start applications or applets. It's crucial to note this vulnerability does not impact Java systems that execute only trusted code, typically found in server setups.

Affected Version(s)

Oracle Java SE 8u491

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.