We are happy to announce the general availability of a Critical Security Patch Update (CSPU) of Liberica JDK versions 6u513, 7u513, 8u504, 11.0.32.1, 17.0.20.1, 21.0.12.1, 25.0.4.1, and 26.0.2.1. CSPU releases are stabilized builds that include patches for Common Vulnerabilities and Exposures (CVE) described in the relevant CVE entries in BellSoft’s Security Advisory and other security fixes.
Liberica JDK CSPU releases are in-line with the new accelerated pace of Java security updates that aims to address critical vulnerabilities more rapidly.
The release contains 29 fixes overall. BellSoft participated in eliminating 11 issues in all releases.
How to keep your runtime secure
BellSoft recommends updating Liberica JDK with each Critical Patch Update (CPU) released in January, April, June, and October every year, and Critical Security Patch Update (CSPU) released in-between to ensure the stable work and secure performance of the runtime.
If you ship applications with a bundled Liberica runtime, we recommend revisiting the full JDK versioning scheme defined in JEP 322, and to make sure your build and deployment tooling correctly handles the emergency patch-release counter used for out-of-cycle security releases.
Liberica JDK updates and patches are available at no cost.
The summary of fixes
4 CVEs patched.
In addition, the release includes a total of 29 security fixes:
- in Liberica 6u513: 3 security fixes;
- in Liberica 7u513: 3 security fixes;
- in Liberica 8u504: 4 security fixes;
- in Liberica 11.0.32.1: 4 security fixes;
- in Liberica 17.0.20.1: 3 security fixes;
- in Liberica 21.0.12.1: 3 security fixes;
- in Liberica 25.0.4.1: 4 security fixes;
- in Liberica 26.0.2.1: 5 security fixes.
List of security issues fixed
|
CVE ID |
cvss score |
component |
module |
Attack vector (network/local) |
Complexity (low/high) |
Privileges (none/low) |
User interaction (none/required) |
Scope (changed/unchanged) |
Confidentiality (low/none/high) |
Integrity (low/none/high) |
Availability (low/none/high) |
|
CVE-2026-70906 |
7.5 |
client-libs |
2d |
network |
low |
none |
none |
unchanged |
none |
none |
high |
|
CVE-2026-61308 |
6.8 |
core-libs |
java.net |
network |
high |
none |
none |
changed |
high |
none |
none |
|
CVE-2026-70907 |
5.3 |
security-libs |
javax.net.ssl |
network |
low |
none |
none |
unchanged |
none |
none |
low |
|
CVE-2026-60589 |
3.7 |
security-libs |
javax.net.crypto |
network |
high |
none |
none |
unchanged |
low |
none |
none |
Summary of fixes in Liberica JDK
CVEs fixed in Liberica per version:
|
CVE ID |
6 |
7 |
8 |
11 |
17 |
21 |
25 |
26 |
|
CVE-2026-70906 |
𑇐 |
𑇐 | ||||||
|
CVE-2026-61308 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
|
CVE-2026-70907 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 | ||
|
CVE-2026-60589 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
𑇐 |
Supported platforms
Liberica JDK is tested and proven to work on a large number of platforms.
Liberica JDK can be run in virtual and cloud environments. The following hypervisors are supported:
- Docker
- KVM
- Microsoft Hyper-V (gen 1 and gen 2)
- VirtualBox
- VMware vSphere Hypervisor
- Solaris Containers & Solaris LDOMs
Liberica JDK supports all major cloud providers, including but not limited to:
- Amazon AWS
- Digital Ocean
- Google Cloud
- Microsoft Azure
- OVH
- Packet
- Scaleway
- VMware Tanzu
Enjoy the most stable runtime!
The CSPU release cycle enables the OpenJDK community to introduce security patches to Java as soon as possible, thus minimizing the risk of attacks on your applications. Download the new Liberica JDK builds now! Click on the button below to head over to Liberica Download Center.





