AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-57237

HIGH · CVSS 7.8 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

A vulnerability in Java allows malicious JavaScript within a PDF to manipulate form field properties, resulting in invalid object states and potential application crashes due to illegal memory access. This high-severity flaw poses significant risks for applications that process PDF files, particularly those in enterprise environments where Java is heavily utilized. Organizations relying on Java for PDF handling should prioritize patching to mitigate the risk of application instability and potential exploitation.

CVE
CVE-2026-57237
Severity
HIGH
CVSS
7.8
EPSS
0.12%
Java

Original NVD Description

When the application opens a PDF and JavaScript modifies the properties of form fields, it causes the state of the underlying objects referenced by the program to become invalid. Eventually, it reads an illegal memory address, which leads to the crash of the application.

Related CVEs

Other vulnerabilities affecting the same vendor(s)