THREAT OPS › Threat News › [NVD] CVE-2026-70906 (HIGH 7.5) — Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 25.0.4 and 26.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful att
[NVD] CVE-2026-70906 (HIGH 7.5) — Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 25.0.4 and 26.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful att
CVE-2026-70906 CVSS: 7.5 HIGH Published: 2026-08-18T21:17:48.393
Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 25.0.4 and 26.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized
MITRE ATT&CK techniques
- Web ServiceT1102
Indicators of compromise
- CVE-2026-70906cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-70906