CVE-2016-3606: Oracle JDK

Critical severity, CVSS 9.6. EPSS: 3.8% chance of exploitation in the next 30 days.

Unspecified vulnerability in Oracle Java SE 7u101 and 8u92 and Java SE Embedded 8u91 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot.

Affected products

  • Oracle JDK: version 1.7.0 only; version 1.8.0 only
  • Oracle JRE: version 1.7.0 only; version 1.8.0 only
  • Oracle Linux: version 5.0 only; version 6.0 only; version 7.0 only

Published 2016-07-21. Last modified 2026-06-17.