Denial of Service Vulnerability in Oracle Java SE Products
CVE-2026-70906
7.5HIGH
What is CVE-2026-70906?
A vulnerability exists in Oracle Java SE that allows unauthenticated attackers with network access to exploit applications utilizing the 2D component. This issue can lead to denial-of-service conditions, causing affected Java SE instances to hang or crash repeatedly. The flaw can be triggered through APIs utilized by web services, especially when handling untrusted code from environments like sandboxed Java Web Start applications or applets. Users are urged to secure their Java deployments to prevent potential exploitation.
Affected Version(s)
Oracle Java SE 25.0.4
Oracle Java SE 26.0.2