Junglewise Threat Intelligence

CVE-2026-71054: Oracle Java SE denial of service in 2D component

CVE-2026-71054 · Severity: medium · CVSS 6.5 · Published 2026-08-26

Executive brief

Oracle Java SE is a foundational runtime environment used to execute Java applications across servers, desktops, and browsers. A flaw in the 2D graphics component allows remote attackers to crash or hang Java applications without authentication, disrupting service availability. This affects both standalone Java applications and browser-based Java applets.

Technical details

The vulnerability is a denial-of-service flaw in the 2D component of Oracle Java SE, exploitable through multiple network protocols. An unauthenticated attacker with network access can trigger a hang or crash by crafting malicious input to the affected APIs, either directly or indirectly through a web service. The issue affects Java SE 7u511 and deployments using Java Web Start or sandboxed applets that load untrusted code. No authentication or user interaction is required; the attack is easily exploitable across the network.

Affected products

  • Oracle Java SE 7u511

Timeline

  • 2026-08-26: disclosed

References

Related threats