[Solved] Another Java vulnerability in 2.7.1
Posted: Mon Feb 23, 2026 6:20 pm
Back again with another detected vulnerability in our Unimus software. We're running 2.7.1 on an Azure virtual server, and our vulnerability scanner is reporting a vulnerability involving the embedded Java instance in the software.
The specific finding is: Unspecified vulnerability in Oracle Java SE, Azul Zulu and Amazon Corretto via vectors related to AWT, JavaFX - CVE-2026-21932
The files it's triggering on are:
C:\Program Files\Unimus\jre17\bin\java.exe
C:\Program Files\Unimus\jre17\bin\javaw.exe
Both versions are 17.0.16.0, and this version apparently is subject to the CVE listed above. I understand from the last post that I made that Unimus doesn't allow external Java code to be executed. Will there be an updated version coming out to address this?
The specific finding is: Unspecified vulnerability in Oracle Java SE, Azul Zulu and Amazon Corretto via vectors related to AWT, JavaFX - CVE-2026-21932
The files it's triggering on are:
C:\Program Files\Unimus\jre17\bin\java.exe
C:\Program Files\Unimus\jre17\bin\javaw.exe
Both versions are 17.0.16.0, and this version apparently is subject to the CVE listed above. I understand from the last post that I made that Unimus doesn't allow external Java code to be executed. Will there be an updated version coming out to address this?