Oracle released Java 26 / JDK 26 as part of its six-month cadence, delivering 10 JDK Enhancement Proposals and a set of incremental changes across performance, networking, language behavior, and security. Security-relevant additions include a preview PEM encoding API in JEP 524 for handling keys, certificates, and certificate revocation lists, plus support for hybrid public key encryption, post-quantum-ready JAR signing, and stronger controls for cryptographic algorithms and legacy keystores. The release also adds HTTP/3 support to the standard HTTP Client API through JEP 517, enabling applications to communicate with HTTP/3 servers with minimal code changes.
Coverage of the release emphasizes that Java 26 is not an LTS release, but still introduces changes intended to keep the platform current for developers adopting newer builds. Additional updates include JEP 500, which warns when deep reflection is used to mutate final fields as part of Java’s “integrity by default” direction, along with performance work such as reduced synchronization in the G1 garbage collector and broader ahead-of-time object caching. The reporting consistently characterizes Java 26 as an incremental platform update with meaningful improvements in cryptography, transport security, and runtime performance, rather than a specific security incident or vulnerability disclosure.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
Oracle said JDK 26 will receive updates until September 2026, when JDK 27 is expected under the project's six-month release cadence. This clarified the support window for the non-LTS release.
Java 26 added HTTP/3 support to the standard HTTP Client API, improved G1 garbage collector throughput, and expanded ahead-of-time object caching and startup optimizations to work with any garbage collector. The release also included features such as lazy constants and removed the obsolete Applet API.
The release introduced security-focused changes including a second preview of a PEM encoding API, hybrid public key encryption, post-quantum-ready JAR signing, and stronger controls for cryptographic algorithms and legacy keystores. It also added compiler warnings for deep reflection that mutates final fields, signaling future enforcement of final-field immutability.
Oracle released Java 26/JDK 26 as the 17th consecutive six-month feature release, introducing 10 JDK Enhancement Proposals across performance, security, networking, and language features. Oracle said the release is not a long-term support version.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.