---
id: CVE-2026-47013
title: 'Vulnerability in Oracle Java SE (component: JavaFX)'
summary: >-
  Vulnerability in Oracle Java SE (component: JavaFX).   The supported version
  that is affected is Oracle Java SE: 8u491. Easily exploitable vulnerability
  allows unauthenticated attacker with network access via multiple protocols to
  compro…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-770
vendor: oracle
product: jdk
affected:
  - jdk = 1.8.0
  - jre = 1.8.0
published: '2026-07-21'
updated: '2026-07-31'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-47013'
references:
  - url: 'https://www.oracle.com/security-alerts/cpujul2026.html'
    label: secalert_us@oracle.com
tags:
  - nvd
epss: 0.00411
epssPercentile: 0.35096
ingestedAt: '2026-08-01T05:11:03.260Z'
---

## Overview

Vulnerability in Oracle Java SE (component: JavaFX).   The supported version that is affected is Oracle Java SE: 8u491. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

## Affected

- `jdk = 1.8.0`
- `jre = 1.8.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
