USN-8681-1: OpenJDK 25 vulnerabilities
It was discovered that the JSSE component of OpenJDK 25 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-46968) It was discovered that the JSSE component of OpenJDK 25 did not correctly authorize users. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-46917) It was discovered that the ImageIO component of OpenJDK 25 did not correctly authorize users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-47010) It was discovered that the 2D component of OpenJDK 25 did not correctly authorize users. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-47021, CVE-2026-47059) It was discovered that the Libraries component of OpenJDK 25 did not correctly authorize users. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-47027) It was discovered that the Security component of OpenJDK 25 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-60147) It was discovered that the Libraries component of OpenJDK 25 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-47063) Lian Owen discovered that the 2D (Little CMS) component of OpenJDK 25 did not correctly handle certain integer arithmetic. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-41254)
CSIRTS triage
- What
- Multiple authentication and authorization flaws in JSSE, ImageIO, 2D, and Libraries components allow remote attackers to read, modify data, or cause denial of service.
- Who is affected
- Systems running OpenJDK 25.
- Urgency
- Moderate; multiple components affected with data confidentiality and denial of service impact, but no active exploitation reported.
- Action
- Update to the patched version of OpenJDK 25 as soon as available.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch OpenJDK
Get an email when a new OpenJDK advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://ubuntu.com/security/notices/USN-8681-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-469680.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-469170.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-470100.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-470210.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-470590.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-470270.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-601470.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-470630.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-412540.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-46968 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-46917 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-47010 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-47021 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-47059 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-47027 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60147 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-47063 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-41254 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] Oracle Java SE: Multiple vulnerabilitiescert-bund
- high[NEW] [high] IBM License Metric Tool: Multiple vulnerabilitiescert-bund
- unknownexploitedMultiple vulnerabilities in IBM products (August 21, 2026)cert-fr-avis
- medium[NEW] [medium] RealObjects PDFreactor: Multiple vulnerabilities enable unspecified attackcert-bund
- unknownexploitedMultiple vulnerabilities in IBM products (August 14, 2026)cert-fr-avis
- unknownDSA-6431-1 openjdk-25 - security updatedebian
- unknownDSA-6425-1 openjdk-21 - security updatedebian
- unknownMultiple vulnerabilities in IBM products (August 07, 2026)cert-fr-avis
- lowCVE-2026-47059: Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition…msrc
- highCVE-2026-47063: Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition…msrc
- mediumCVE-2026-60147: Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition…msrc
- mediumCVE-2026-46917: Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition…msrc
More from Ubuntu Security Notices
- unknownUSN-8683-1: libheif vulnerabilities2026-08-26
- unknownUSN-8682-1: Bind vulnerabilities2026-08-26
- unknownUSN-8659-4: Linux kernel (Oracle) vulnerability2026-08-26
- unknownUSN-8666-2: Linux kernel (Azure) vulnerabilities2026-08-25
- unknownUSN-8630-5: Linux kernel (Raspberry Pi) vulnerabilities2026-08-25