USN-8681-1: OpenJDK 25 vulnerabilities
It was discovered that the JSSE component of OpenJDK 25 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-46968) It was discovered that the JSSE component of OpenJDK 25 did not correctly authorize users. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-46917) It was discovered that the ImageIO component of OpenJDK 25 did not correctly authorize users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-47010) It was discovered that the 2D component of OpenJDK 25 did not correctly authorize users. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-47021, CVE-2026-47059) It was discovered that the Libraries component of OpenJDK 25 did not correctly authorize users. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-47027) It was discovered that the Security component of OpenJDK 25 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-60147) It was discovered that the Libraries component of OpenJDK 25 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-47063) Lian Owen discovered that the 2D (Little CMS) component of OpenJDK 25 did not correctly handle certain integer arithmetic. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-41254)
CSIRTS triage
- What
- Multiple authentication and authorization flaws in JSSE, ImageIO, 2D, and Libraries components allow remote attackers to read, modify data, or cause denial of service.
- Who is affected
- Systems running OpenJDK 25.
- Urgency
- Moderate; multiple components affected with data confidentiality and denial of service impact, but no active exploitation reported.
- Action
- Update to the patched version of OpenJDK 25 as soon as available.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch OpenJDK
Get an email when a new OpenJDK advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://ubuntu.com/security/notices/USN-8681-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-469680.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-469170.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-470100.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-470210.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-470590.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-470270.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-601470.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-470630.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-412540.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-46968 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-46917 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-47010 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-47021 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-47059 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-47027 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60147 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-47063 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-41254 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [hoch] IBM License Metric Tool: Mehrere Schwachstellencert-bund
- medium[UPDATE] [mittel] Oracle Java SE: Mehrere Schwachstellencert-bund
- unknownMultiples vulnérabilités dans les produits IBM (11 septembre 2026)cert-fr-avis
- highexploited[UPDATE] [hoch] IBM QRadar SIEM: Mehrere Schwachstellencert-bund
- unknownMultiples vulnérabilités dans les produits IBM (04 septembre 2026)cert-fr-avis
- unknownUSN-8689-1: OpenJDK 26 vulnerabilitiesubuntu
- unknownexploitedMultiples vulnérabilités dans les produits IBM (28 août 2026)cert-fr-avis
- unknownexploitedMultiple vulnerabilities in IBM products (August 21, 2026)cert-fr-avis
- medium[NEW] [medium] RealObjects PDFreactor: Multiple vulnerabilities enable unspecified attackcert-bund
- unknownexploitedMultiple vulnerabilities in IBM products (August 14, 2026)cert-fr-avis
- unknownDSA-6431-1 openjdk-25 - security updatedebian
- unknownDSA-6425-1 openjdk-21 - security updatedebian
More from Ubuntu Security Notices
- unknownUSN-8571-2: Apache HTTP Server regression2026-09-10
- unknownUSN-8747-1: Beets vulnerability2026-09-10
- unknownUSN-8746-1: libEBML vulnerability2026-09-10
- unknownUSN-8745-1: KissFFT vulnerabilities2026-09-10
- unknownUSN-8748-1: Linux kernel (NVIDIA) vulnerabilities2026-09-10