PatchSiren cyber security CVE debrief
CVE-2026-60164 Oracle Corporation CVE debrief
The CVE-2026-60164 vulnerability affects Oracle Java SE, specifically the JavaFX component, in version 8u491. This difficult-to-exploit vulnerability allows unauthenticated attackers with network access via multiple protocols to compromise the system, requiring human interaction. Successful attacks can result in unauthorized read access to a subset of accessible data. The vulnerability primarily affects client-side deployments running sandboxed Java Web Start applications or sandboxed Java applets that load and run untrusted code. It does not apply to server deployments that load and run only trusted code. Organizations should be aware of this vulnerability and take necessary actions to mitigate the risk, especially those with client-side deployments.
- Vendor
- Oracle Corporation
- Product
- Oracle Java SE
- CVSS
- LOW 3.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-08-03
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-08-03
Who should care
Organizations using Oracle Java SE 8u491, particularly those with client-side deployments that load and run untrusted code, should be aware of this vulnerability and take necessary actions to mitigate the risk. This includes reviewing and updating security configurations, applying vendor patches or updates, and monitoring for suspicious activity.
Technical summary
The vulnerability in Oracle Java SE (component: JavaFX) allows unauthenticated attackers with network access via multiple protocols to compromise the system. Successful attacks require human interaction and can result in unauthorized read access to a subset of accessible data. The CVSS 3.1 Base Score is 3.1 (Confidentiality impacts), with a vector of (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N). This vulnerability primarily affects client-side deployments running sandboxed Java Web Start applications or sandboxed Java applets that load and run untrusted code.
Defensive priority
Oracle Java SE vulnerability allows unauthenticated network attackers to compromise the system with human interaction required, resulting in unauthorized read access to a subset of accessible data.
Recommended defensive actions
- Inventory and verify affected Oracle Java SE deployments
- Apply vendor patches or updates
- Monitor for suspicious activity
- Implement compensating controls
- Review and update security configurations
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
Evidence notes
The vulnerability affects Oracle Java SE 8u491, particularly in clients running sandboxed Java Web Start applications or sandboxed Java applets that load and run untrusted code. This vulnerability does not apply to Java deployments in servers that load and run only trusted code. The CVSS 3.1 Base Score is 3.1 (Confidentiality impacts), with a vector of (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).
Official resources
-
CVE-2026-60164 CVE record
CVE.org
-
CVE-2026-60164 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:17.120Z and has not been modified since then.