Product of Oracle

Java Runtime Environment (JRE)

As of , 4 Oracle Java Runtime Environment (JRE) vulnerabilities are on CISA's list of exploited vulnerabilities, 2 of them used in ransomware campaigns; 0 were added in 2026. Patch first: CVE-2010-0840.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2010-0840JRE UnspecifiedOracle Java Runtime Environment (JRE)Patch this weekMetasploit module; EPSS 0.96; verified Exploit-DB entry0.96
2CVE-2013-0422JRE Remote Code ExecutionOracle Java Runtime Environment (JRE)Patch this weekRansomware use; Metasploit module; EPSS 0.97; verified Exploit-DB entry0.97
3CVE-2013-0431JRE Sandbox BypassOracle Java Runtime Environment (JRE)Patch this weekRansomware use; Metasploit module; EPSS 0.90; verified Exploit-DB entry0.90
4CVE-2013-2423JRE UnspecifiedOracle Java Runtime Environment (JRE)Patch this weekMetasploit module; EPSS 0.85; verified Exploit-DB entry0.85

Added each year

12342022: 4420222023: nonenone20232024: nonenone20242025: nonenone20252026: nonenone2026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20224
2023none
2024none
2025none
2026none

Used in ransomware

Changes CISA made to these entries

  1. CVE-2013-0422 Oracle Java Runtime Environment (JRE)Ransomware use: Unknown to Known.

Every change we recorded