Network Vulnerability in Oracle Java SE and GraalVM Products
CVE-2026-70907
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 18 August 2026
What is CVE-2026-70907?
A vulnerability has been identified in Oracle Java SE and GraalVM products, specifically within the JSSE component. This vulnerability allows unauthenticated attackers with network access via TLS to compromise affected systems. It affects several versions of Oracle Java SE and GraalVM, enabling attackers to potentially cause a partial denial-of-service (DoS) condition. Notably, exploitation occurs without the need for untrusted Java Web Start applications or applets, allowing attackers to exploit the vulnerability through standard web services by supplying crafted data to APIs.
Affected Version(s)
Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition Oracle Java SE:8u501
Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition Oracle Java SE:11.0.32
Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition Oracle Java SE:17.0.20