CVE-2026-21947
published 2026-01-20CVE-2026-21947: Vulnerability in Oracle Java SE (component: JavaFX). Supported versions that are affected are Oracle Java SE: 8u471-b50. Difficult to exploit vulnerability…
PriorityP411low3.1CVSS 3.1
AVNACHPRNUIRSUCNILAN
EPSS
0.20%
10.6th percentile
Vulnerability in Oracle Java SE (component: JavaFX). Supported versions that are affected are Oracle Java SE: 8u471-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjfx | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle_corporation | oracle_java_se | — | — |
CVSS provenance
nvdv3.13.1LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
osv3.1LOW
vendor_debian3.1LOW
vendor_oracle3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Oracle Java SE 8u471-b50 JavaFX cross site scripting (EUVD-2026-3562 / Nessus ID 297729)
vuldb·2026-06-11·CVSS 3.1
CVE-2026-21947 [LOW] Oracle Java SE 8u471-b50 JavaFX cross site scripting (EUVD-2026-3562 / Nessus ID 297729)
A vulnerability was found in Oracle Java SE 8u471-b50. It has been classified as critical. This affects an unknown function of the component JavaFX. The manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2026-21947. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
GHSA
GHSA-998g-2mp2-f264: Vulnerability in Oracle Java SE (component: JavaFX)
ghsa_unreviewed·2026-01-21
CVE-2026-21947 [LOW] CWE-79 GHSA-998g-2mp2-f264: Vulnerability in Oracle Java SE (component: JavaFX)
Vulnerability in Oracle Java SE (component: JavaFX). Supported versions that are affected are Oracle Java SE: 8u471-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java depl
OSV
CVE-2026-21947: Vulnerability in Oracle Java SE (component: JavaFX)
osv·2026-01-20·CVSS 3.1
CVE-2026-21947 [LOW] CVE-2026-21947: Vulnerability in Oracle Java SE (component: JavaFX)
Vulnerability in Oracle Java SE (component: JavaFX). Supported versions that are affected are Oracle Java SE: 8u471-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java depl
Oracle
Oracle Oracle Java SE Risk Matrix: JavaFX — CVE-2026-21947
vendor_oracle·2026-01-15·CVSS 3.1
CVE-2026-21947 [LOW] Oracle Oracle Java SE Risk Matrix: JavaFX — CVE-2026-21947
Oracle Oracle Java SE Risk Matrix: JavaFX vulnerability
CVE: CVE-2026-21947
CVSS: 3.1
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
Debian
CVE-2026-21947: openjfx - Vulnerability in Oracle Java SE (component: JavaFX). Supported versions that ar...
vendor_debian·2026·CVSS 3.1
CVE-2026-21947 [LOW] CVE-2026-21947: openjfx - Vulnerability in Oracle Java SE (component: JavaFX). Supported versions that ar...
Vulnerability in Oracle Java SE (component: JavaFX). Supported versions that are affected are Oracle Java SE: 8u471-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java depl
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-21947 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.1
CVE-2026-21947 [LOW] CVE-2026-21947 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21947 :
Amazon Corretto JDK vulnerability analysis and mitigation
Vulnerability in Oracle Java SE (component: JavaFX). Supported versions that are affected are Oracle Java SE: 8u471-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely
Wiz
CVE-2026-21925 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.8
CVE-2026-21925 [MEDIUM] CVE-2026-21925 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21925 :
Amazon Corretto JDK vulnerability analysis and mitigation
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: RMI). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle GraalVM for JDK: 17.0.17 and 21.0.9; Oracle GraalVM Enterprise Edition: 21.3.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterpr
Wiz
CVE-2026-21945 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-21945 [HIGH] CVE-2026-21945 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21945 :
Amazon Corretto JDK vulnerability analysis and mitigation
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle GraalVM for JDK: 17.0.17 and 21.0.9; Oracle GraalVM Enterprise Edition: 21.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE, Oracle GraalV
Wiz
CVE-2026-21932 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.4
CVE-2026-21932 [HIGH] CVE-2026-21932 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21932 :
Amazon Corretto JDK vulnerability analysis and mitigation
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: AWT, JavaFX). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle GraalVM for JDK: 17.0.17 and 21.0.9; Oracle GraalVM Enterprise Edition: 21.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Java SE, Oracle GraalVM for JDK, Oracle Gra
Wiz
CVE-2026-21933 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.1
CVE-2026-21933 [MEDIUM] CVE-2026-21933 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21933 :
Amazon Corretto JDK vulnerability analysis and mitigation
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle GraalVM for JDK: 17.0.17 and 21.0.9; Oracle GraalVM Enterprise Edition: 21.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Java SE, Oracle GraalVM for JDK, Oracle Graa
2026-01-20
Published