CVE-2026-60589 is a difficult-to-exploit vulnerability in the Security component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition. Affected versions are Oracle Java SE 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, and 26.0.2; Oracle GraalVM for JDK 17.0.20 and 21.0.12; and Oracle GraalVM Enterprise Edition 21.3.19. The issue is associated with resource resolving behavior in the JDK security area and can be triggered by supplying crafted data to exposed APIs in the affected component over the network via multiple protocols. Oracle states exploitation does not require untrusted Java Web Start applications or untrusted Java applets and can occur in server-side usage such as a web service that passes attacker-controlled input into the vulnerable APIs.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability referenced in Red Hat advisory RHSA-2026:55774 affecting Red Hat Enterprise Linux 7 OpenJDK 8 packages; specific flaw details are not provided in the content.
A JDK vulnerability addressed in the Java 11 OpenJDK Extended Lifecycle Support security update for Red Hat Enterprise Linux 7, 8, and 9.
A security-component vulnerability in Oracle Java SE / GraalVM components that can be exploited by an unauthenticated attacker over multiple protocols to gain unauthorized read access to a subset of accessible data.
A specific OpenJDK vulnerability referenced by the Nessus plugin, but the content does not describe the flaw type or impact in detail.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.