CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-60589: Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Or

lowCVSS 3.7CVE-2026-60589

CSIRTS triage

vendor: Oracleproduct: Oracle Java SEOtheraffected: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2
What
A vulnerability exists in the Security component of Oracle Java SE (specific technical details not provided in the advisory).
Who is affected
Oracle Java SE users running the listed affected versions and Oracle GraalVM for JDK 17.0.20.
Urgency
Low severity (CVSS 3.7) and not exploited; include in routine patch management cycles.
Action
Apply Oracle's Java SE security update to the affected versions listed in the advisory.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Oracle Java SE

Get an email when a new Oracle Java SE advisory drops — max one per day, one-click unsubscribe.

Details

Source
Microsoft Security Response Center (INTL · vendor-psirt · site)
Severity
low — CVSS 3.7
Published
2026-08-11
Exploitation
Not in CISA KEV at last sync

Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-60589

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-60589coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Microsoft Security Response Center