USN-8689-1: OpenJDK 26 vulnerabilities
It was discovered that the JSSE component of OpenJDK 26 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-46968) It was discovered that the JSSE component of OpenJDK 26 did not correctly authorize users. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-46917) It was discovered that the ImageIO component of OpenJDK 26 did not correctly authorize users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-47010) It was discovered that the 2D component of OpenJDK 26 did not correctly authorize users. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-47021, CVE-2026-47059) It was discovered that the Libraries component of OpenJDK 26 did not correctly authorize users. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-47027) It was discovered that the Security component of OpenJDK 26 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-60147) It was discovered that the Libraries component of OpenJDK 26 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-47063) Lian Owen discovered that the 2D (Little CMS) component of OpenJDK 26 did not correctly handle certain integer arithmetic. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-41254)
CSIRTS triage
- What
- Multiple authentication, authorization, and denial-of-service vulnerabilities exist in JSSE, ImageIO, 2D, and Libraries components of OpenJDK 26.
- Who is affected
- Systems running OpenJDK 26 are affected; the vulnerabilities allow remote attackers to read, modify data, or cause denial of service.
- Urgency
- High urgency; multiple remote vulnerabilities in core Java components require prompt patching.
- Action
- Update OpenJDK to the latest patched version of 26 or to a newer stable release.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch OpenJDK
Get an email when a new OpenJDK advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://ubuntu.com/security/notices/USN-8689-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-469680.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-469170.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-470100.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-470210.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-470590.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-470270.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-601470.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-470630.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-412540.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-46968 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-46917 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-47010 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-47021 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-47059 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-47027 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60147 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-47063 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-41254 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [mittel] Oracle Java SE: Mehrere Schwachstellencert-bund
- medium[UPDATE] [mittel] RealObjects PDFreactor: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriffcert-bund
- high[UPDATE] [hoch] IBM License Metric Tool: Mehrere Schwachstellencert-bund
- unknownMultiples vulnérabilités dans les produits IBM (11 septembre 2026)cert-fr-avis
- highexploited[UPDATE] [hoch] IBM QRadar SIEM: Mehrere Schwachstellencert-bund
- unknownMultiples vulnérabilités dans les produits IBM (04 septembre 2026)cert-fr-avis
- unknownexploitedMultiples vulnérabilités dans les produits IBM (28 août 2026)cert-fr-avis
- unknownUSN-8681-1: OpenJDK 25 vulnerabilitiesubuntu
- unknownexploitedMultiple vulnerabilities in IBM products (August 21, 2026)cert-fr-avis
- unknownexploitedMultiple vulnerabilities in IBM products (August 14, 2026)cert-fr-avis
- unknownDSA-6431-1 openjdk-25 - security updatedebian
- unknownDSA-6425-1 openjdk-21 - security updatedebian
More from Ubuntu Security Notices
- unknownUSN-8563-5: nginx vulnerability2026-09-14
- unknownUSN-8751-1: Urwid vulnerabilities2026-09-14
- unknownUSN-8750-1: FFmpeg vulnerabilities2026-09-14
- unknownUSN-8749-1: CivetWeb vulnerabilities2026-09-14
- unknownUSN-8571-2: Apache HTTP Server regression2026-09-10