eclipse security advisories
7 threat alerts tracking vulnerabilities and security advisories that affect eclipse products.
Vulnios monitors eclipse CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent eclipse security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2026-16441 — eclipse — openj9
In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method has been recompiled as abstract, execution is incorrectly delegated to an interface defa
criticalCVE-2026-16441Critical Vulnerability: CVE-2026-16439 — eclipse — openj9
In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow.
criticalCVE-2026-16439Critical Vulnerability: CVE-2026-10050 — eclipse — jetty
In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP did not specify explicitl
criticalCVE-2026-10050Critical Vulnerability: CVE-2026-24457 — eclipse — openmq
An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorize
criticalCVE-2026-24457Critical Vulnerability: CVE-2026-9158 — eclipse — 4diac_forte
In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling pointer. This allows subsequent commands to access free
criticalCVE-2026-9158Critical Vulnerability: CVE-2024-9342 — eclipse — glassfish
In Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed login attempts. GlassFish 8.0.3 adds automatic attack p
criticalCVE-2024-9342Critical Vulnerability: CVE-2017-7649 — eclipse — kura
The network enabled distribution of Kura before 2.1.0 takes control over the device's firewall setup but does not allow IPv6 firewall rules to be configured. Still the Equinox console port 5002 is lef
criticalCVE-2017-7649
Track eclipse exposure across your environment
Vulnios automatically cross-references your asset inventory against new eclipse CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan