CERT-FR Flags Oracle GraalVM/Java SE Flaws
CERT-FR advisory details multiple Oracle GraalVM vulnerabilities enabling remote code execution and denial of service.
CERT-FR issued an advisory covering multiple vulnerabilities in Oracle Java SE, specifically affecting Oracle GraalVM Enterprise Edition and Oracle GraalVM for JDK 17, JDK 21, and standalone GraalVM 25.x releases. The flaws allow an attacker to achieve remote arbitrary code execution or trigger a remote denial of service condition, though the advisory does not detail specific attack vectors or confirm active exploitation.
Three CVEs are referenced (CVE-2026-83357, CVE-2026-83368, CVE-2026-83408), tracked under Oracle's September 2026 Critical Patch Update bulletin (cspusep2026). No indicators of compromise or exploitation in the wild are mentioned. Affected organizations running the listed GraalVM versions should apply Oracle's official patches referenced in the CPU bulletin as soon as possible, prioritizing systems exposed to untrusted input given the RCE potential.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1185
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free