Skip to main content

Threats Tagged 'java'

View all threats tagged with 'java'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: java

Threats Tagged 'java'

Click on any threat for detailed analysis and mitigation recommendations

Oracle released its September 2026 Critical Security Patch Update (CSPU) addressing 672 unique CVEs with 673 patches across 17 product families. The update includes 104 critical severity patches and 503 high severity patches. Oracle E-Business Suite received the highest number of patches (159), followed by Oracle Fusion Middleware (153). Several vulnerabilities can be exploited remotely without authentication. Patches are available in the official advisory.

Join the discussion

CVE-2026-85228 is an integer overflow vulnerability in the tensor buffer validation component of the Deep Java Library (DJL), an open-source Java framework for deep learning maintained by Amazon. The flaw occurs when a crafted tensor payload declares a shape whose computed byte size exceeds the 32-bit signed integer range, causing the size to wrap and allowing an undersized buffer to pass validation. This leads to out-of-bounds reads during tensor operations. Exploitation could allow a remote, unauthenticated attacker to access adjacent process memory or cause a denial of service. A fix has been released in DJL version 0.37.0. Users are advised to upgrade to this version or later. No workaround other than upgrading is available, but limiting tensor input to trusted sources can reduce risk until patched.

Join the discussion

CVE-2026-85786 is a memory-amplification denial of service vulnerability in the Amazon ion-java library. It arises from an incomplete fix for a previous vulnerability (CVE-2026-75936) related to GZIP auto-decompression. The issue allows denial of service via highly compressed data expansion. Versions of ion-java prior to 1.12.1 are affected. The vulnerability has been addressed in ion-java version 1.12.1, and no workarounds are available.

HighVulnerability#cloud#dos#java
Join the discussion

CVE-2026-85656 is an OS command injection vulnerability in the Amazon log4j-cve-2021-44228-hotpatch tool for Amazon Linux. This tool injects a Java agent into running JVM processes to patch the Log4j CVE-2021-44228 vulnerability without restarting the process. The flaw allows a local user to execute arbitrary commands with root privileges if the Java process executable path contains embedded newline characters. Versions up to and including 1.3-8.amzn2 are affected. The issue is fixed in version 1.3-9.amzn2.

Join the discussion

CVE-2026-83497 is a vulnerability in the OpenSearch SQL Plugin that allows a remote authenticated user with basic read/search permissions to execute arbitrary code on the server by supplying a crafted cursor parameter to the plugins/sql endpoint. This issue affects both the open-source self-managed OpenSearch SQL Plugin versions 2.8 through 3.6 and the Amazon OpenSearch Service managed versions 2.9 through 3.5. The vulnerability is addressed in OpenSearch SQL Plugin versions 2.19.6 and 3.7, and in the Amazon OpenSearch Service via service software updates for affected versions 2.9 to 3.5. No workarounds are available, and users are advised to upgrade or apply the managed service update promptly.

CriticalVulnerability#cloud#java
Join the discussion

CVE-2026-75935 is a high-severity vulnerability in the Amazon Ion Java library, affecting versions prior to 1.12.0. It involves memory allocation with an excessive size value, leading to a denial of service condition through memory amplification. This vulnerability allows an attacker to cause a denial of service by triggering large memory preallocation based on declared lengths in data processing.

Join the discussion

Bulletin ID: 2026-051-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/01/2026 12:45 PM PDT Description: The AWS Advanced JDBC Wrapper is an open-source JDBC driver wrapper that extends a JDBC driver to enable Amazon Aurora and AWS Cloud features such as failover handling and caching. We identified CVE-2026-14265, an issue in the RemoteQueryCachePlugin of the AWS Advanced JDBC Wrapper. When this plugin is enabled, query results read from the shared Redis/Valkey cache are deserialized without class filtering. An actor with write access to the shared cache infrastructure could insert a crafted serialized Java object that, when read by an application, results in execution of arbitrary code on the application server. Impacted versions: >=3.3.0 AND <=4.0.0 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

Join the discussion

Bulletin ID: 2026-011-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/03/31 10:15 AM PDT Description: AWS Common Runtime library is used by several AWS SDKs to communicate with event-stream services (Ex. Kinesis, Transcribe). We identified CVE-2026-5190. AWS Common Runtime event-stream decoder component before 0.6.0 might allow a third party operating a server to cause memory corruption leading to arbitrary code execution on a client application that processes crafted event-stream messages. Impacted versions: - aws-c-event-stream < 0.6.0and the following higher level libraries that expose event-stream functionality - aws-iot-device-sdk-cpp-v2 < 1.42.1 - aws-iot-device-sdk-java-v2 < 1.30.1 - aws-iot-device-sdk-python-v2 < 1.28.2 - aws-iot-device-sdk-js-v2 < 1.25.1 - aws-sdk-swift < 1.6.70 - aws-sdk-cpp < 1.11.764 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

Join the discussion

Oracle released its August 2026 Critical Security Patch Update (CSPU) addressing 925 unique CVEs with 943 patches across 23 product families. This update includes 154 critical severity patches, representing 16.3% of all patches, with Oracle Fusion Middleware receiving the highest number of patches at 262. The CSPU is part of Oracle's monthly patch cycle introduced in May 2026 to address high-severity issues more rapidly. Many vulnerabilities can be exploited remotely without authentication. Patches for all affected products are available in the official August 2026 advisory.

Join the discussion

A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files. [...]

Join the discussion

Showing 1 to 10 of 35 results

Filters:Tag: java
Page 1 of 4
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses