Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4356 articles · 196349 vulns · 36/41 feeds (7d)
← Back to list
5.3
CVE-2026-47027PATCHED
oracle · graalvm

CVE-2026-47027: Vulnerability in Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491,

Description

Vulnerability in Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

Affected Products

VendorProductVersions
oraclegraalvm8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
amazoncorrettocert_advisory90%
azulazul zulucert_advisory90%
ibmlicense metric toolcert_advisory90%
ibmvioscert_advisory90%
ibmaixcert_advisory90%

References

  • https://www.oracle.com/security-alerts/cpujul2026.html(vendor-advisory)

Related News (9 articles)

Tier B
BSI Advisories2d ago
[NEU] [hoch] IBM License Metric Tool: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR3d ago
Multiples vulnérabilités dans les produits IBM (21 août 2026)
→ No new info (linked only)
Tier B
BSI Advisories6d ago
[NEU] [mittel] RealObjects PDFreactor: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff
→ No new info (linked only)
Tier B
BSI Advisories7d ago
[NEU] [hoch] IBM AIX und VIOS: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR10d ago
Multiples vulnérabilités dans les produits IBM (14 août 2026)
→ No new info (linked only)
Tier B
CERT-FR17d ago
Multiples vulnérabilités dans les produits IBM (07 août 2026)
→ No new info (linked only)
Tier B
CERT-FR32d ago
Multiples vulnérabilités dans Oracle Java SE (23 juillet 2026)
→ No new info (linked only)
Tier B
BSI Advisories33d ago
[NEU] [mittel] Oracle Java SE: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB33d ago
CVE-2026-47027 | Oracle Java SE up to 26.0.1 Libraries resource consumption
→ No new info (linked only)
CVSS 3.15.3 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://www.oracle.com/security-alerts/cpujul2026.html
PublishedJul 21, 2026
Trending Score35
Source articles9
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-47057
CVE-2026-47057: Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491,
Trending: 38
HIGHCVE-2026-47063
CVE-2026-47063: Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Trending: 38
CRITICALCVE-2026-60782
CVE-2026-60782: Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versi
Trending: 35
MEDIUMCVE-2026-47021
CVE-2026-47021: Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Trending: 35
CRITICALCVE-2026-70926
CVE-2026-70926: Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supp
Trending: 35

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 21, 2026
Discovered by ZDM
Jul 21, 2026
Patch Available
Jul 23, 2026