Skip to content
Critical Security Flaws in Oracle Linux Java 21 OpenJDK

Critical Security Flaws in Oracle Linux Java 21 OpenJDK

First seen 14 Sep 2026, 12:22 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 14, 2026 at 13:48 UTC
  • Chained vulnerabilities in Java 21 OpenJDK allow admin control.
  • Affected versions include Oracle Linux 8 and 9.
  • Administrators must update to mitigate risks from CVEs.

Oracle has issued critical security advisories for Java 21 OpenJDK, affecting Oracle Linux 8 and 9. Chained vulnerabilities allow attackers to gain administrative control over systems running vulnerable versions. The affected versions include java-21-openjdk-21.0.12.1.1-1.1.0.1 for Oracle Linux 8 and java-21-openjdk-21.0.12.1.1-1.2.0.1 for Oracle Linux 9. The vulnerabilities are linked to CVEs published between April and July 2026, including CVE-2026-41254 and CVE-2026-47021. Administrators are urged to update to the latest versions to mitigate risks. The updates are available as of September 14, 2026, and the advisories emphasize the urgency of applying these patches due to the potential for exploitation. Oracle has provided a vendor bug URL for further details.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-04-18
CVE-2026-41254 published
A critical vulnerability in Java 21 OpenJDK was disclosed, affecting multiple systems.
Linuxsecurity
2026-07-21
Multiple CVEs published
CVE-2026-47021, CVE-2026-46968, CVE-2026-47059, CVE-2026-46917, CVE-2026-47027, CVE-2026-47010, and CVE-2026-47063 were disclosed, impacting Java 21 OpenJDK.
Linuxsecurity
2026-07-21
CVE-2026-47021 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-21
CVE-2026-46968 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-21
CVE-2026-47059 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-21
CVE-2026-46917 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-21
CVE-2026-47027 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-21
CVE-2026-47010 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-21
CVE-2026-47063 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-14
Critical security advisories issued
Oracle released advisories for Java 21 OpenJDK vulnerabilities, urging immediate updates.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track CVE-2026-41254 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed