OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-15639

CRITICAL · CVSS 9.3 EPSS 0.39%

Source: NVD + CISA KEV + EPSS · Published 2026-09-16 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

A critical vulnerability in Java allows attackers to create malicious links that, when clicked by legitimate users, execute arbitrary JavaScript in their browsers. This could lead to unauthorized actions, data theft, or further exploitation of the user's system. Organizations utilizing Java in their web applications should prioritize patching this vulnerability to mitigate potential risks.

CVE
CVE-2026-15639
Severity
CRITICAL
CVSS
9.3
EPSS
0.39%
Java

Original NVD Description

An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the attacker.