PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60164 Oracle Corporation CVE debrief

The CVE-2026-60164 vulnerability affects Oracle Java SE, specifically the JavaFX component, in version 8u491. This difficult-to-exploit vulnerability allows unauthenticated attackers with network access via multiple protocols to compromise the system, requiring human interaction. Successful attacks can result in unauthorized read access to a subset of accessible data. The vulnerability primarily affects client-side deployments running sandboxed Java Web Start applications or sandboxed Java applets that load and run untrusted code. It does not apply to server deployments that load and run only trusted code. Organizations should be aware of this vulnerability and take necessary actions to mitigate the risk, especially those with client-side deployments.

Vendor
Oracle Corporation
Product
Oracle Java SE
CVSS
LOW 3.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-08-03
Advisory published
2026-07-21
Advisory updated
2026-08-03

Who should care

Organizations using Oracle Java SE 8u491, particularly those with client-side deployments that load and run untrusted code, should be aware of this vulnerability and take necessary actions to mitigate the risk. This includes reviewing and updating security configurations, applying vendor patches or updates, and monitoring for suspicious activity.

Technical summary

The vulnerability in Oracle Java SE (component: JavaFX) allows unauthenticated attackers with network access via multiple protocols to compromise the system. Successful attacks require human interaction and can result in unauthorized read access to a subset of accessible data. The CVSS 3.1 Base Score is 3.1 (Confidentiality impacts), with a vector of (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N). This vulnerability primarily affects client-side deployments running sandboxed Java Web Start applications or sandboxed Java applets that load and run untrusted code.

Defensive priority

Oracle Java SE vulnerability allows unauthenticated network attackers to compromise the system with human interaction required, resulting in unauthorized read access to a subset of accessible data.

Recommended defensive actions

  • Inventory and verify affected Oracle Java SE deployments
  • Apply vendor patches or updates
  • Monitor for suspicious activity
  • Implement compensating controls
  • Review and update security configurations
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance

Evidence notes

The vulnerability affects Oracle Java SE 8u491, particularly in clients running sandboxed Java Web Start applications or sandboxed Java applets that load and run untrusted code. This vulnerability does not apply to Java deployments in servers that load and run only trusted code. The CVSS 3.1 Base Score is 3.1 (Confidentiality impacts), with a vector of (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:17.120Z and has not been modified since then.