# CERT-FR Flags Oracle GraalVM/Java SE Flaws

Published: 2026-09-16 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/3e5d5b70-ad72-51d1-9bfd-49a25d0049a3/cert-fr-flags-oracle-graalvm-java-se-flaws

> CERT-FR advisory details multiple Oracle GraalVM vulnerabilities enabling remote code execution and denial of service.

CERT-FR issued an advisory covering multiple vulnerabilities in Oracle Java SE, specifically affecting Oracle GraalVM Enterprise Edition and Oracle GraalVM for JDK 17, JDK 21, and standalone GraalVM 25.x releases. The flaws allow an attacker to achieve remote arbitrary code execution or trigger a remote denial of service condition, though the advisory does not detail specific attack vectors or confirm active exploitation.

Three CVEs are referenced (CVE-2026-83357, CVE-2026-83368, CVE-2026-83408), tracked under Oracle's September 2026 Critical Patch Update bulletin (cspusep2026). No indicators of compromise or exploitation in the wild are mentioned. Affected organizations running the listed GraalVM versions should apply Oracle's official patches referenced in the CPU bulletin as soon as possible, prioritizing systems exposed to untrusted input given the RCE potential.

## Mentioned in this report

- Vulnerabilities: CVE-2026-83357, CVE-2026-83368, CVE-2026-83408

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1185

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/3e5d5b70-ad72-51d1-9bfd-49a25d0049a3/cert-fr-flags-oracle-graalvm-java-se-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
