Junglewise Threat Intelligence

CVE-2026-70906: Oracle Java SE denial of service in 2D component

CVE-2026-70906 · Severity: high · CVSS 7.5 · Published 2026-08-18

Executive brief

Oracle Java SE contains a vulnerability in its 2D graphics component that allows an attacker to remotely crash or hang Java applications without authentication. This affects Java applications running on client machines, including web-based applets and remote code execution scenarios, resulting in potential service disruption and negative user experience.

Technical details

This is a denial-of-service vulnerability in Oracle Java SE's 2D graphics component that can be exploited via multiple network protocols. The vulnerability is easily exploitable and requires no authentication or user interaction; an unauthenticated attacker with network access can trigger the flaw by supplying malicious data to APIs in the 2D component, such as through a web service endpoint. Successful exploitation results in a hang or repeated crash of the affected Java process, causing availability disruption. The vulnerability affects Java SE versions 25.0.4 and 26.0.2, and is particularly concerning for sandboxed Java applets and Java Web Start applications that load untrusted code from the internet.

Affected products

  • Oracle Java SE 25.0.4, 26.0.2

Timeline

  • 2026-08-18: disclosed

References

Related threats