Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4508 articles · 223853 vulns · 37/41 feeds (7d)
← Back to list
7.4
CVE-2026-47058PATCHED
oracle · jre

CVE-2026-47058: Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491,

Description

Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data as well as unauthorized access to critical data or complete access to all Oracle Java SE accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).

Affected Products

VendorProductVersions
oraclejre8u491, 8u491-perf, 11.0.31

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
amazoncorrettocert_advisory90%
azulazul zulucert_advisory90%
ibmqradar siemcert_advisory90%
ibmaixcert_advisory90%
ibmvioscert_advisory90%

References

  • https://www.oracle.com/security-alerts/cpujul2026.html(vendor-advisory)

Related News (15 articles)

Tier B
CERT-FR3d ago
Multiples vulnérabilités dans les produits IBM (25 septembre 2026)
→ No new info (linked only)
Tier B
CERT-FR10d ago
Multiples vulnérabilités dans les produits IBM (18 septembre 2026)
→ No new info (linked only)
Tier B
CERT-FR17d ago
Multiples vulnérabilités dans les produits IBM (11 septembre 2026)
→ No new info (linked only)
Tier B
CERT-FR24d ago
Multiples vulnérabilités dans les produits IBM (04 septembre 2026)
→ No new info (linked only)
Tier B
CERT-FR31d ago
Multiples vulnérabilités dans les produits IBM (28 août 2026)
→ No new info (linked only)
Tier B
BSI Advisories31d ago
[NEU] [hoch] IBM QRadar SIEM: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
BSI Advisories37d ago
[NEU] [hoch] IBM License Metric Tool: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR38d ago
Multiples vulnérabilités dans les produits IBM (21 août 2026)
→ No new info (linked only)
Tier B
BSI Advisories39d ago
[NEU] [hoch] IBM App Connect Enterprise: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
BSI Advisories41d ago
[NEU] [hoch] IBM AIX und VIOS: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR45d ago
Multiples vulnérabilités dans les produits IBM (14 août 2026)
→ No new info (linked only)
Tier B
CERT-FR52d ago
Multiples vulnérabilités dans les produits IBM (07 août 2026)
→ No new info (linked only)
Tier B
CERT-FR67d ago
Multiples vulnérabilités dans Oracle Java SE (23 juillet 2026)
→ No new info (linked only)
Tier B
BSI Advisories67d ago
[NEU] [mittel] Oracle Java SE: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB68d ago
CVE-2026-47058 | Oracle Java SE 8u491/8u491-perf/11.0.31 Scripting improper authorization
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.4 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://www.oracle.com/security-alerts/cpujul2026.html
PublishedJul 21, 2026
Last enriched68d agov2
Trending Score35
Source articles15
Independent3
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-47063
CVE-2026-47063: Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Trending: 39
HIGHCVE-2026-47057
CVE-2026-47057: Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491,
Trending: 38
MEDIUMCVE-2026-60147
CVE-2026-60147: Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Trending: 36
MEDIUMCVE-2026-47021
CVE-2026-47021: Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Trending: 36
MEDIUMCVE-2026-47027
CVE-2026-47027: Vulnerability in Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491,
Trending: 36

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 21, 2026
Discovered by ZDM
Jul 21, 2026
Updated: severity, cweIds
Jul 21, 2026
Patch Available
Aug 1, 2026

Version History

v2
Last enriched 68d ago
v2Tier C68d ago

Severity updated from HIGH to CRITICAL and CWE-285 (Improper Authorization) added based on vulnerability classification and root cause description.

severitycweIds
via VulDB
v168d ago

Initial creation