PatchSiren cyber security CVE debrief
CVE-2026-47057 Oracle Corporation CVE debrief
The CVE-2026-47057 vulnerability is a critical issue in the Scripting component of Oracle Java SE, affecting versions 8u491, 8u491-perf, and 11.0.31. This vulnerability allows unauthenticated attackers with network access to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE. The CVSS 3.1 Base Score is 7.5, indicating high severity. Organizations must apply patches immediately to prevent exploitation. The vulnerability can be exploited through APIs in the Scripting component, and it also affects Java deployments running sandboxed Java Web Start applications or sandboxed Java applets that load and run untrusted code. It is crucial for organizations using Oracle Java SE versions 8u491, 8u491-perf, and 11.0.31 to apply patches immediately and monitor for suspicious network activity.
- Vendor
- Oracle Corporation
- Product
- Oracle Java SE
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-08-03
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-08-03
Who should care
Organizations using Oracle Java SE versions 8u491, 8u491-perf, and 11.0.31 should apply patches immediately. This includes enterprises relying on Java for critical operations, as well as developers using Java for client-side applications. IT teams responsible for Java SE deployments must prioritize patching to prevent exploitation. Additionally, security teams should monitor for suspicious network activity and implement compensating controls for exposed systems.
Technical summary
The CVE-2026-47057 vulnerability is in the Scripting component of Oracle Java SE, affecting versions 8u491, 8u491-perf, and 11.0.31. It is easily exploitable by unauthenticated attackers with network access via multiple protocols, leading to unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE. The vulnerability's CVSS 3.1 Base Score is 7.5, with a vector of (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). This vulnerability can be exploited through APIs in the Scripting component, and it also affects Java deployments running sandboxed Java Web Start applications or sandboxed Java applets that load and run untrusted code.
Defensive priority
Oracle Java SE vulnerability allows unauthenticated network attackers to cause a hang or crash, requiring immediate patching.
Recommended defensive actions
- Apply the Oracle Java SE patch immediately
- Inventory and update affected Java SE versions
- Monitor for suspicious network activity
- Implement compensating controls for untrusted code execution
- Review and update vulnerability management processes
- Conduct a thorough review of Java SE deployments
- Verify patch deployment and system integrity
Evidence notes
The CVE-2026-47057 vulnerability affects Oracle Java SE versions 8u491, 8u491-perf, and 11.0.31. It allows unauthenticated attackers with network access to cause a hang or crash. The CVSS 3.1 Base Score is 7.5, indicating high severity. This vulnerability can be exploited through APIs in the Scripting component, and it also affects Java deployments running sandboxed Java Web Start applications or sandboxed Java applets that load and run untrusted code.
Official resources
-
CVE-2026-47057 CVE record
CVE.org
-
CVE-2026-47057 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:11.483Z and has not been modified since then.