OVERVIEW CVE-2026-22016 is a vulnerability in the JAXP component of Oracle Java SE and related products, affecting multiple versions including Java SE 8u481 through 26, GraalVM for JDK 17.0.18 and 21.0.10, and GraalVM Enterprise Edition 21.3.17. The vulnerability allows unauthenticated attackers to gain unauthorized access to critical data through network-accessible APIs, and can be exploited via web services, Java Web Start applications, or sandboxed applets. SEVERITY The vulnerability carries a CVSS 3.1 score of 7.5 (HIGH) with a network-based attack vector requiring low complexity and no user interaction or privileges. The attack results in high confidentiality impact, potentially exposing all accessible data within affected Java environments, though it does not enable unauthorized modification or denial of service. The vulnerability is easily exploitable due to its minimal prerequisites for attack execution. EXPLOITATION STATUS This vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog and shows no evidence of active exploitation in the wild. The EPSS score of 0.00033 indicates minimal real-world exploitation probability at present, and community attention remains low with the vulnerability marked as inactive on threat tracking systems. However, organizations should prioritize patching given the high CVSS score and ease of exploitation once widely understood.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.8.0:update481:*:*:-:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.8.0:update481:*:*:enterprise_performance_pack:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.8.0:update481_b50:*:*:-:*:*:* | ||
11.0.30CPE matchmatch criteria | cpe:2.3:a:oracle:jre:11.0.30:*:*:*:*:*:*:* | ||
17.0.18CPE matchmatch criteria | cpe:2.3:a:oracle:jre:17.0.18:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
OpenJDK 26 vulnerabilities
May 28, 2026OpenJDK 25 vulnerabilities
May 28, 2026CRaC JDK 25 vulnerabilities
May 28, 2026CRaC JDK 21 vulnerabilities
May 28, 2026CRaC JDK 17 vulnerabilities
May 28, 2026OpenJDK 11 vulnerabilities
May 28, 2026OpenJDK 8 vulnerabilities
May 28, 2026