What's New in This Update
This release contains fixes for security vulnerabilities and bug fixes. Oracle strongly recommends that all Java SE users upgrade to this release.
- Security Fixed vulnerability in JNDI component allowing remote code execution (CVE-2025-21893)
- Security Addressed TLS handshake bypass in JSSE (CVE-2025-21847)
- Security Patched XML External Entity processing flaw in JAXP (CVE-2025-21902)
- Security Resolved deserialization issue in RMI registry (CVE-2025-21815)
- Security Fixed certificate validation bypass in PKI path building (CVE-2025-21778)
- Bug Fix Corrected GC pause time regression in CMS collector under heavy heap pressure
- Bug Fix Fixed intermittent ClassNotFoundException with custom classloaders in modular deployments
- Performance Improved JIT compilation throughput for lambda expressions by 12%
- Performance Reduced startup time for applications using ServiceLoader
- Performance Improved telemetry agent stability and reduced memory footprint by 34%
- Bug Fix Fixed intermittent telemetry connection timeout behind corporate proxies
- Bug Fix Resolved timezone data inconsistency for Asia/Shanghai (JDK-8327419)