PT-2026-3682 · Oracle+3 · Graalvm For Jdk 21.0.9+13

Mingijung

·

Published

2026-01-20

·

Updated

2026-05-08

·

CVE-2026-21932

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Oracle Java SE versions 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1 Oracle GraalVM for JDK versions 17.0.17 and 21.0.9 Oracle GraalVM Enterprise Edition version 21.3.16
Description An easily exploitable issue exists in Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition, specifically within the AWT and JavaFX components. An unauthenticated attacker with network access, utilizing multiple protocols, can compromise the software. Successful exploitation requires interaction from a user other than the attacker. The issue primarily affects Java deployments that load and execute untrusted code, such as Java Web Start applications or applets relying on the Java sandbox for security. Exploitation may lead to unauthorized modification, creation, or deletion of critical data accessible by Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition.
Recommendations Oracle Java SE version 8u471-b50 should be updated. Oracle Java SE version 8u471 should be updated. Oracle Java SE version 8u471-perf should be updated. Oracle Java SE version 11.0.29 should be updated. Oracle Java SE version 17.0.17 should be updated. Oracle Java SE version 21.0.9 should be updated. Oracle Java SE version 25.0.1 should be updated. Oracle GraalVM for JDK version 17.0.17 should be updated. Oracle GraalVM for JDK version 21.0.9 should be updated. Oracle GraalVM Enterprise Edition version 21.3.16 should be updated.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2026-00681
BIT-JAVA-2026-21932
BIT-JAVA-MIN-2026-21932
BIT-JRE-2026-21932
CVE-2026-21932
OPENSUSE-SU-2026:10091-1
OPENSUSE-SU-2026:10092-1
OPENSUSE-SU-2026:10093-1
OPENSUSE-SU-2026:10108-1
OPENSUSE-SU-2026:10136-1
OPENSUSE-SU-2026:20126-1
OPENSUSE-SU-2026:20134-1
OPENSUSE-SU-2026:20143-1
SUSE-SU-2026:0341-1
SUSE-SU-2026:0342-1
SUSE-SU-2026:0363-1
SUSE-SU-2026:0382-1
SUSE-SU-2026:0389-1
SUSE-SU-2026:0390-1
SUSE-SU-2026:0414-1
SUSE-SU-2026:0415-1
SUSE-SU-2026:0441-1
SUSE-SU-2026:0504-1
SUSE-SU-2026:20190-1
SUSE-SU-2026:20199-1
SUSE-SU-2026:20215-1
USN-7995-1
USN-7996-1
USN-7997-1
USN-7998-1
USN-8000-1
USN-8001-1
USN-8002-1
USN-8003-1

Affected Products

Graalvm Enterprise Edition 21.3.16
Graalvm For Jdk 17.0.17
Graalvm For Jdk 21.0.9
Java Platform
Java Se 11.0.29
Java Se 17.0.17
Java Se 21.0.9
Java Se 25.0.1
Java Se 8U471
Java Se 8U471-B50
Java Se 8U471-Perf
Linuxmint
Red Os
Ubuntu