We are happy to announce the general availability of a Critical Patch Update (CPU) of Liberica JDK versions 6u511, 7u511, 8u501, 11.0.31.0.1, 17.0.19.0.1, 21.0.11.0.1, 25.0.3.0.1. CPU releases are stabilized builds that include patches for Common Vulnerabilities and Exposures (CVE) described in the relevant CVE entries in BellSoft’s Security Advisory.
BellSoft is one of only three companies including Oracle that release CPU builds aimed at eliminating known security issues without disrupting the production environment.
In addition, we release PSU versions 8u502, 11.0.32, 17.0.20, 21.0.12, 25.0.4, and 26.0.2 with non-critical fixes and general improvements.
The release contains 1252 fixes and backports overall. BellSoft participated in eliminating 35 issues in all releases.
How to keep your runtime secure
BellSoft recommends updating Liberica JDK with each Critical Patch Update (CPU) to ensure the stable work and secure performance of the runtime.
CPUs are scheduled for release in January, April, June, and October every year.
Liberica JDK updates and patches are available at no cost.
The summary of fixes
- 18 security issues (CVEs) fixed.
- 89 total security fixes (+ 22 additional non-security fixes) in CPU release:
- in Liberica 6u511: 13 security fixes + 11 additional fixes;
- in Liberica 7u511: 13 security fixes + 11 additional fixes;
- in Liberica 8u501: 13 security fixes;
- in Liberica 11.0.31.0.1: 14 security fixes;
- in Liberica 17.0.19.0.1: 12 security fixes;
- in Liberica 21.0.11.0.1: 12 security fixes;
- in Liberica 25.0.3.0.1: 12 security fixes.
In addition, PSU releases include a total of 1141 fixes and backports:
- in Liberica 8u502: 13 security fixes (+ 5 in FX) + 38 additional fixes (+ 10 in FX);
- in Liberica 11.0.32: 14 security fixes (+ 5 in FX) + 54 additional fixes (+ 9 in FX);
- in Liberica 17.0.20: 12 security fixes (+ 5 in FX) + 203 additional fixes (+ 14 in FX);
- in Liberica 21.0.12: 12 security fixes (+ 6 in FX) + 265 additional fixes (+ 13 in FX).
- in Liberica 25.0.4: 12 security fixes (+ 6 in FX) + 233 additional fixes (+ 11 in FX);
- in Liberica 26.0.2: 12 security fixes (+ 6 in FX) + 166 additional fixes (+ 17 in FX).
List of security issues fixed
|
CVE ID |
cvss score |
component |
module |
Attack vector (network/local) |
Complexity (low/high) |
Privileges (none/low) |
User interaction (none/required) |
Scope (changed/unchanged) |
Confidentiality (low/none/high) |
Integrity (low/none/high) |
Availability (low/none/high) |
|
CVE-2026-47057 |
7.5 |
core-libs |
javax.script |
network |
low |
none |
none |
unchanged |
none |
none |
high |
|
CVE-2026-41254 |
7.5 |
client-libs |
2d |
network |
low |
none |
none |
unchanged |
none |
none |
high |
|
CVE-2026-47063 |
7.5 |
security-libs |
java.security |
network |
low |
none |
none |
unchanged |
none |
high |
none |
|
CVE-2026-47058 |
7.4 |
core-libs |
javax.script |
network |
high |
none |
none |
unchanged |
high |
high |
none |
|
CVE-2026-60147 |
6.5 |
security-libs |
java.security |
network |
low |
none |
none |
unchanged |
low |
low |
none |
|
CVE-2026-46968 |
5.9 |
security-libs |
javax.net.ssl |
network |
high |
none |
none |
unchanged |
none |
high |
none |
|
CVE-2026-47027 |
5.3 |
security-libs |
java.security |
network |
low |
none |
none |
unchanged |
none |
none |
low |
|
CVE-2026-47021 |
5.3 |
client-libs |
2d |
network |
low |
none |
none |
unchanged |
none |
none |
low |
|
CVE-2026-46917 |
5.3 |
security-libs |
javax.net.ssl |
network |
low |
none |
none |
unchanged |
none |
none |
low |
|
CVE-2026-47059 |
5.9 |
client-libs |
2d |
network |
high |
none |
none |
unchanged |
none |
none |
low |
|
CVE-2026-47010 |
3.7 |
client-libs |
javax.imageio |
network |
high |
none |
none |
unchanged |
none |
low |
none |
|
CVE-2026-47013 |
5.3 |
javafx |
graphics |
network |
low |
none |
none |
unchanged |
none |
none |
low |
|
CVE-2026-47030 |
3.1 |
javafx |
web |
network |
high |
none |
required |
unchanged |
none |
low |
none |
|
CVE-2026-47034 |
3.1 |
javafx |
media |
network |
high |
none |
required |
unchanged |
none |
low |
none |
|
CVE-2026-47035 |
3.1 |
javafx |
media |
network |
high |
none |
required |
unchanged |
none |
low |
none |
|
CVE-2026-60164 |
3.1 |
javafx |
web |
network |
high |
none |
required |
unchanged |
low |
none |
none |
|
CVE-2026-60165 |
3.1 |
javafx |
media |
network |
high |
none |
required |
unchanged |
none |
low |
none |
|
CVE-2026-60166 |
3.1 |
javafx |
media |
network |
high |
none |
required |
unchanged |
low |
none |
none |
Summary of fixes in Liberica JDK
CVEs fixed in Liberica per version:
|
CVE ID |
8 |
11 |
17 |
21 |
25 |
26 |
|
CVE-2026-47057 |
𑇐 |
𑇐 | ||||
|
CVE-2026-41254 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
|
CVE-2026-47063 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
|
CVE-2026-47058 |
𑇐 |
𑇐 | ||||
|
CVE-2026-60147 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
|
CVE-2026-46968 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
|
CVE-2026-47027 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
|
CVE-2026-47021 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
|
CVE-2026-46917 |
|
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
|
CVE-2026-47059 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
|
CVE-2026-47010 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
|
CVE-2026-47013 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
|
CVE-2026-47030 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
|
CVE-2026-47034 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
|
CVE-2026-47035 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
|
CVE-2026-60164 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
|
CVE-2026-60165 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
|
CVE-2026-60166 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
