Available Security Updates

Browse and install the latest security patches for Java SE Runtime Environments.




Showing 1–8 of 247 updates
JSU-2025-0198 — Java SE Critical Patch Update: Remote Code Execution Critical
Mar 11, 2025 Patch Size: 48.2 MB Downloads: 1,247,832
Addresses a critical vulnerability in the HotSpot VM that allows remote attackers to execute arbitrary code via a crafted serialized object. Immediate installation is strongly recommended for all production environments.
JSU-2025-0195 — Unsafe Deserialization in JNDI Subsystem Critical
Mar 4, 2025 Patch Size: 35.7 MB Downloads: 983,105
Resolves unsafe deserialization vulnerability in the Java Naming and Directory Interface (JNDI) that could allow an attacker to achieve remote code execution through LDAP/RMI lookup injection.
JSU-2025-0191 — TLS Certificate Chain Validation Bypass High
Feb 18, 2025 Patch Size: 22.1 MB Downloads: 742,518
Fixes a flaw in JSSE TLS implementation where certificate chain validation can be bypassed under specific conditions involving intermediate CA certificates with path length constraints.
JSU-2025-0187 — XML External Entity Expansion Denial of Service Medium
Feb 4, 2025 Patch Size: 18.4 MB Downloads: 561,229
Addresses a vulnerability in the built-in XML parser where recursive entity expansion can cause excessive memory consumption, leading to denial of service conditions on affected systems.
JSU-2025-0183 — JMX Remote Access Control Weakness Low
Jan 21, 2025 Patch Size: 12.8 MB Downloads: 328,442
Corrects an access control issue in JMX Remote where certain MBean operations could be invoked without proper authentication when specific JMX connector configurations are used.
JSU-2025-0179 — Kerberos Authentication Ticket Forgery High
Jan 14, 2025 Patch Size: 28.3 MB Downloads: 614,771
Patches a vulnerability in the Java GSS/Kerberos implementation where an attacker with network access could forge Kerberos service tickets, potentially gaining unauthorized access to protected resources.
JSU-2025-0174 — Security Manager Sandbox Escape Critical
Jan 7, 2025 Patch Size: 41.6 MB Downloads: 1,102,447
Addresses a critical sandbox escape vulnerability allowing untrusted code to break out of the Java Security Manager restrictions and execute arbitrary system commands with the privileges of the JVM process.
JSU-2024-0168 — Cryptographic Key Generation Weakness High
Dec 10, 2024 Patch Size: 19.7 MB Downloads: 891,334
Fixes a weakness in the SecureRandom implementation on certain platforms where insufficient entropy during key generation could result in predictable cryptographic keys.