Denial of Service Vulnerability in Oracle Java SE Products
CVE-2026-70906

7.5HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-70906?

A vulnerability exists in Oracle Java SE that allows unauthenticated attackers with network access to exploit applications utilizing the 2D component. This issue can lead to denial-of-service conditions, causing affected Java SE instances to hang or crash repeatedly. The flaw can be triggered through APIs utilized by web services, especially when handling untrusted code from environments like sandboxed Java Web Start applications or applets. Users are urged to secure their Java deployments to prevent potential exploitation.

Affected Version(s)

Oracle Java SE 25.0.4

Oracle Java SE 26.0.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.