PatchSiren cyber security CVE debrief
CVE-2026-60164 Oracle Corporation CVE debrief
The CVE-2026-60164 vulnerability affects Oracle Java SE, specifically the JavaFX component, in version 8u491. This difficult-to-exploit vulnerability allows unauthenticated attackers with network access via multiple protocols to compromise the system, requiring human interaction. Successful attacks can result in unauthorized read access to a subset of accessible data. The vulnerability primarily affects client-side deployments running sandboxed Java Web Start applications or sandboxed Java applets that load and run untrusted code. It does not apply to server deployments that load and run only trusted code. Organizations should be aware of this vulnerability and take necessary actions to mitigate the risk, especially those with client-side deployments.
- Vendor
- Oracle Corporation
- Product
- Oracle Java SE
- CVSS
- LOW 3.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-08-03
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-08-03
Who should care
Organizations using Oracle Java SE 8u491, particularly those with client-side deployments that load and run untrusted code, should be aware of this vulnerability and take necessary actions to mitigate the risk. This includes reviewing and updating security configurations, applying vendor patches or updates, and monitoring for suspicious activity.
Technical summary
The vulnerability in Oracle Java SE (component: JavaFX) allows unauthenticated attackers with network access via multiple protocols to compromise the system. Successful attacks require human interaction and can result in unauthorized read access to a subset of accessible data. The CVSS 3.1 Base Score is 3.1 (Confidentiality impacts), with a vector of (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N). This vulnerability primarily affects client-side deployments running sandboxed Java Web Start applications or sandboxed Java applets that load and run untrusted code.
Defensive priority
Oracle Java SE vulnerability allows unauthenticated network attackers to compromise the system with human interaction required, resulting in unauthorized read access to a subset of accessible data.
Recommended defensive actions
- Inventory and verify affected Oracle Java SE deployments
- Apply vendor patches or updates
- Monitor for suspicious activity
- Implement compensating controls
- Review and update security configurations
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
Evidence notes
The vulnerability affects Oracle Java SE 8u491, particularly in clients running sandboxed Java Web Start applications or sandboxed Java applets that load and run untrusted code. This vulnerability does not apply to Java deployments in servers that load and run only trusted code. The CVSS 3.1 Base Score is 3.1 (Confidentiality impacts), with a vector of (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).
Sources and references
Verified primary and authoritative sources
-
CVE-2026-60164 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-60164
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-60164 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-60164
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cpujul2026.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.