What is CVE-2026-46917?
This critical vulnerability resides in the JSSE component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition, potentially allowing an unauthenticated attacker with network access to compromise the system. Affected versions include various updates of Java SE 11, 17, 21, 25, and 26, requiring immediate patching to the latest security update provided by Oracle.
Azərbaycanca: Bu kritik zəiflik Oracle Java SE, Oracle GraalVM for JDK və Oracle GraalVM Enterprise Edition məhsullarının JSSE komponentində aşkarlanıb. TLS/SSL şifrələmə protokolunu idarə edən bu zəiflikdən uzaqdan autentifikasiya olunmamış hücumçu istifadə edərək məxfi məlumatları əldə edə bilər. Təsirə məruz qalan versiyalara dərhal Oracle-ın təqdim etdiyi təhlükəsizlik yeniləməsi tətbiq edilməlidir.
Related CVEs
link basis: shared vendor: Oracle
FAQ2
Which Oracle products are affected by CVE-2026-46917?
This critical vulnerability resides in the JSSE component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition.
How can one protect against this vulnerability?
Affected versions require immediate patching to the latest security update provided by Oracle.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.