CVE-2026-21925Patch(oracle / graalvm)

LOWCVSS 4.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch oracle graalvm systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: RMI). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle GraalVM for JDK: 17.0.17 and 21.0.9; Oracle GraalVM Enterprise Edition: 21.3.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).

1.0/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • graalvm
  • graalvm_for_jdk
  • jdk
  • jre

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-02-03); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
graalvmgraalvm_for_jdkjdkjre

6 versions affected across 4 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-03: 1Mentions · 2026-02-10: 1Patch / Workaround · 2026-02-03: 1Patch / Workaround · 2026-02-10: 1Technical Details · 2026-02-03: 1Technical Details · 2026-02-10: 102-0302-10
Signal classification1 categories
Patch
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    URGENT: Patch #Java 17 OpenJDK on SUSE now. New update fixes 4 flaws (CVE-2026-21925 to 21945), including a 7.5 CVSS DoS bug. Affects #SLES, #openSUSE Leap, HPC. Read more: 👉 https://tinyurl.com/r7amu53n #security https://t.co/Zy3JfLn8OQ

    Post summary

    SUSE has released a patch for Java 17 OpenJDK that fixes four CVEs, including a 7.5‑score DoS vulnerability.

    0000065
    1.3K followersView on X
  • ThreatCluster@threatcluster
    Patch

    OpenJDK 8, 11, 17, 21 and CRaC JDK 21 affected by RMI info theft bug CVE-2026-21925, allowing unauthenticated remote TCP connections without endpoint checks. Ubuntu patches available. #Java https://threatcluster.io/cluster/multiple-openjdk-versions-exposed-to-remote-information-thef-2cf80b64

    Post summary

    The post reports that OpenJDK and CRaC JDK versions are affected by CVE‑2026‑21925, an RMI information‑theft vulnerability, and that Ubuntu has released patches.

    0000054
    80 followersView on X
CPE platform detail17 entries

17 of 17 entries

PartVendorProductVersionTarget SWTarget HW
Apporaclegraalvm21.3.16--
Apporaclegraalvm_for_jdk17.0.17--
Apporaclegraalvm_for_jdk21.0.9--
Apporaclejdk1.8.0--
Apporaclejdk1.8.0--
Apporaclejdk1.8.0--
Apporaclejdk11.0.29--
Apporaclejdk17.0.17--
Apporaclejdk21.0.9--
Apporaclejdk25.0.1--
Apporaclejre1.8.0--
Apporaclejre1.8.0--
Apporaclejre1.8.0--
Apporaclejre11.0.29--
Apporaclejre17.0.17--
Apporaclejre21.0.9--
Apporaclejre25.0.1--

Explore more