It was discovered that the RMI component of OpenJDK 11 would establish RMI TCP endpoint connections to a remote host without setting an endpoint identification algorithm. An unauthenticated remote attacker could possibly use this issue to steal sensitive information. ( CVE-2026-21925 ) Mingijung discovered that the AWT and JavaFX componenets of OpenJDK 11 could run programs if Desktop.browse() was supplied a filename as a URI. An unauthenticated remote attacker could possibly use this issue to execute arbitrary code. ( CVE-2026-21932 ) Zhihui Chen discovered that the Networking component of OpenJDK 11 was suceptible to a CRLF injection vulnerability via the HttpServer class. An unauthenticated remote attacker could possibly use this issue to modify files or leak sensitive information. (
It was discovered that the RMI component of OpenJDK 11 would establish RMI TCP endpoint connections to a remote host without setting an endpoint identification algorithm. An unauthenticated remote attacker could possibly use this issue to steal sensitive information. ( CVE-2026-21925 )
Mingijung discovered that the AWT and JavaFX componenets of OpenJDK 11 could run programs if Desktop.browse() was supplied a filename as a URI. An unauthenticated remote attacker could possibly use this issue to execute arbitrary code. ( CVE-2026-21932 )
Zhihui Chen discovered that the Networking component of OpenJDK 11 was suceptible to a CRLF injection vulnerability via the HttpServer class. An unauthenticated remote attacker could possibly use this issue to modify files or leak sensitive information. (
It was discovered that the RMI component of OpenJDK 11 would establish RMI TCP endpoint connections to a remote host without setting an endpoint identification algorithm. An unauthenticated remote attacker could possibly use this issue to steal sensitive information. ( CVE-2026-21925 ) Mingijung discovered that the AWT and JavaFX componenets of OpenJDK 11 could run programs if Desktop.browse() was supplied a filename as a URI. An unauthenticated remote attacker could possibly use this issue to execute arbitrary code. ( CVE-2026-21932 ) Zhihui Chen discovered that the Networking component of OpenJDK 11 was suceptible to a CRLF injection vulnerability via the HttpServer class. An unauthenticated remote attacker could possibly use this issue to modify files or leak sensitive information. ( CVE-2026-21933 ) Ireneusz Pastusiak discovered that the Security component of OpenJDK 11 failed to verify provided URIs point to a legitimate source when AIA is enabled. An unauthenticated remote attacker could possibly use this issue to redirect users to malicious hosts. ( CVE-2026-21945 ) In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information:
It was discovered that the RMI component of OpenJDK 11 would establish RMI TCP endpoint connections to a remote host without setting an endpoint identification algorithm. An unauthenticated remote attacker could possibly use this issue to steal sensitive information. ( CVE-2026-21925 )
Mingijung discovered that the AWT and JavaFX componenets of OpenJDK 11 could run programs if Desktop.browse() was supplied a filename as a URI. An unauthenticated remote attacker could possibly use this issue to execute arbitrary code. ( CVE-2026-21932 )
Zhihui Chen discovered that the Networking component of OpenJDK 11 was suceptible to a CRLF injection vulnerability via the HttpServer class. An unauthenticated remote attacker could possibly use this issue to modify files or leak sensitive information. ( CVE-2026-21933 )
Ireneusz Pastusiak discovered that the Security component of OpenJDK 11 failed to verify provided URIs point to a legitimate source when AIA is enabled. An unauthenticated remote attacker could possibly use this issue to redirect users to malicious hosts. ( CVE-2026-21945 )
In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes.
Please see the following for more information:
This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart Java applications to make all the necessary changes.
The problem can be corrected by updating your system to the following package versions:
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
