Networking Vulnerability in Oracle Java SE and GraalVM Products
CVE-2026-61308
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 18 August 2026
What is CVE-2026-61308?
A vulnerability in Oracle's Java SE and GraalVM products allows unauthenticated attackers with network access to potentially compromise the affected systems. This flaw, rooted in the Networking component, impacts critical versions of Oracle Java SE and its GraalVM variants. Attackers can exploit this vulnerability through APIs in the Networking component, posing serious risks for unauthorized access to sensitive data. The vulnerability's reach may extend to other products relying on Java deployments, particularly in environments utilizing sandboxed applications that execute untrusted code from the internet. This emphasizes the need for prompt patching and security measures to mitigate risks.
Affected Version(s)
Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition Oracle Java SE:8u501
Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition Oracle Java SE:11.0.32
Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition Oracle Java SE:17.0.20