cbcvebase.
CVE-2026-10037
published 2026-07-08

CVE-2026-10037: A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files marked as…

PriorityP349high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.12%
2.2th percentile
A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is installed. A compromised or malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk can write a malicious .jar file to the host file system, set its executable bit, and trigger the handler to execute arbitrary code outside of the sandbox environment.

Affected

5 ranges
VendorProductVersion rangeFixed in
canonicalubuntu< 3.70+nmu1ubuntu1.22.04.13.70+nmu1ubuntu1.22.04.1
canonicalubuntu< 3.70+nmu1ubuntu1.24.04.13.70+nmu1ubuntu1.24.04.1
canonicalubuntu< 3.74ubuntu1.13.74ubuntu1.1
canonicalubuntu< 3.75ubuntu1.13.75ubuntu1.1
ubuntumailcap
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.