Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Oracle Java SE and Java SE Embedded Libraries Component Deserialization Vulnerability

Vulnerability

A deserialization vulnerability has been identified in the Libraries component of Oracle Java SE and Java SE Embedded. This vulnerability allows remote attackers to impact the confidentiality, integrity, and availability of the affected system. The issue arises in specific versions of Oracle Java SE (6u95, 7u80, and 8u45) and Java SE Embedded (7u75 and 8u33). The vulnerability can be exploited by an untrusted Java application or applet that bypasses Java sandbox restrictions.

Impact

Exploitation of this vulnerability leads to a deserialization issue in the ObjectInputStream.readSerialData() method, which can be manipulated to affect the application's behavior or data processing.

Remediation

Users are advised to upgrade to the latest versions of Oracle Java SE or Java SE Embedded. For Oracle Java SE, the latest release can be downloaded from the Oracle website or via the Oracle Update mechanism on Windows and Mac OS X. Instructions for updating Oracle Java Embedded can be found in the Oracle Java SE Embedded Critical Patch Update Advisory.

Added: May 15, 2026, 9:06 AM
Updated: May 15, 2026, 9:06 AM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
10.0
exploitability
5.8
remediation
7.7
relevance
0.0
threat
9.3
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.