Documented CVEs
6 vulnerabilities cataloged in the Hermes intelligence repository.
| Parameter | Technical Specification |
|---|---|
| Official Name | Oracle Java SE & OpenJDK Runtime |
| Vendor / Project | oracle |
| Canonical ID | oracle:java |
| Versioning Scheme | semver |
| CPE Identifiers | cpe:2.3:a:oracle:jre:*:*:*:*:*:*:*:*cpe:2.3:a:oracle:jdk:*:*:*:*:*:*:*:*cpe:2.3:a:oracle:graalvm:*:*:*:*:*:*:*:*cpe:2.3:a:oracle:graalvm_enterprise_edition:*:*:*:*:*:*:*:* |
| Overall Posture | HIGH |
| Recommended Safe Release | lcms2 2.19 |
Documented CVEs
6 vulnerabilities cataloged in the Hermes intelligence repository.
CISA KEV Entries
0 flaws with confirmed active in-the-wild exploitation.
Weaponized Exploits
6 vulnerabilities with publicly available PoCs or weaponized exploit tooling.
Remediation Target
Recommended upgrade to lcms2 2.19 to neutralize known flaws.
Progression of Hermes Threat Score (HTS) posture and maximum EPSS probability over the last 30 days:
0 / 100
= Stable over 30d
0.5 %
= Stable over 30d
0
No active KEV
| CVE | CVSS Score | EPSS Probability | CISA KEV | Affected Versions | Fixed In | Hermes Analysis |
|---|---|---|---|---|---|---|
| CVE-2026-62574 | 7.8 (HIGH) | 0.1% | No | < v8u501 | 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2 | Analysis β |
| CVE-2026-41254 | 7.5 (HIGH) | 0.4% | No | < vlcms2 2.19 | lcms2 2.19, Java SE 8u492, 11.0.32, 17.0.20, 21.0.12 | Analysis β |
| CVE-2026-47057 | 7.5 (HIGH) | 0.5% | No | < v8u492 | 8u492, 11.0.32 | Analysis β |
| CVE-2026-47063 | 7.5 (HIGH) | 0.3% | No | < v8u492 | 8u492, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2 | Analysis β |
| CVE-2026-47058 | 7.4 (HIGH) | 0.4% | No | < v8u492 | 8u492, 11.0.32 | Analysis β |
| CVE-2026-61308 | 6.8 (MEDIUM) | 0.3% | No | < v8u502 | 8u502, 11.0.33, 17.0.21, 21.0.13, 25.0.5, 26.0.3 | Analysis β |
Are you operating Oracle Java SE & OpenJDK Runtime in your infrastructure? Inspect your running build to evaluate applicability, confidence score, and security deltas: