Junglewise Threat Intelligence

CVE-2026-47013: Oracle Java SE partial denial of service in JavaFX

CVE-2026-47013 · Severity: medium · CVSS 5.3 · Published 2026-07-21

Technologies: Oracle Java SE (JavaFX). Vendors: Oracle.

Executive brief

A vulnerability exists in the JavaFX component of Oracle Java SE, which is used for creating desktop and rich internet applications. An unauthenticated attacker could exploit this flaw over a network to cause a partial denial of service, potentially disrupting the availability of applications that rely on this software. This issue is particularly relevant for environments running sandboxed Java applications, such as those loaded from the internet.

Technical details

This vulnerability is located in the JavaFX component of Oracle Java SE version 8u491. It is classified as an easily exploitable flaw that allows an unauthenticated attacker with network access via multiple protocols to compromise the system. The primary impact is a partial denial of service (DoS) affecting the availability of the Java runtime. The vulnerability can be triggered through APIs in the JavaFX component, for instance, by a web service providing malicious data to those APIs. It also affects client-side deployments running sandboxed Java Web Start applications or applets that execute untrusted code from the internet. Oracle addressed this in the July 2026 Critical Patch Update.

Affected products

  • Oracle Java SE (JavaFX) 8u491

Timeline

  • 2026-07-21: advisory: Initial publication by Oracle and NVD

References

Related threats