FYI...
End of Public Updates for Oracle JDK 8
> http://www.oracle.co...eol-135779.html
Sep 12, 2017 - "... Oracle will not post further updates of Java SE 8 to its public download sites for commercial use after September 2018. Customers who need continued access to critical bug fixes and security fixes as well as general maintenance for Java SE 8 or previous versions can get long term support through Oracle Java SE Advanced, Oracle Java SE Advanced Desktop, or Oracle Java SE Suite. All other users are recommended to upgrade to the latest major releases of the Oracle JDK or OpenJDK.
Oracle does -not- plan to migrate desktops from Java 8 to Java 9 through the auto update feature. Instead of relying on a pre-installed standalone JRE, we will begin encouraging application developers to deliver JREs with their applications. More details will be made available through early 2018...
Long Term Support...
** Java SE 9 will be a short term release, and users should immediately transition to the next release (18.3) when available.
*** Oracle has proposed a new version scheme (YY.M) starting in March, 2018. Java SE 18.3 will be a short term release and users should transition to the next release when available."
___
Java 8 u144 released
- https://www.java.com...load/manual.jsp
July 26, 2017
Blog: https://blogs.oracle...-8u144-released
July 26, 2017 - "... This is an out-of-cycle patch release to address a -regression- reported in Java WebStart. You can download the latest JDK releases from the Java SE Downloads page*. Oracle strongly recommends that all Java SE users upgrade to these releases..."
* http://www.oracle.co...oads/index.html
Remove Older Versions: Java Uninstall tool:
- https://www.java.com...installtool.jsp
"Out-of-date versions of Java on your computer may present a serious security risk. If out-of-date versions are found, this tool will help you remove them..."
Release notes: http://www.oracle.co...es-3838694.html
Bug Fixes: http://www.oracle.co...es-3839149.html
____
Java 8 Update 141 released
- https://www.java.com...load/manual.jsp
July 18, 2017
Text Form of Risk Matrix for Oracle Java SE
- http://www.oracle.co...36625.html#JAVA
- http://www.oracle.co...ml#AppendixJAVA
"This Critical Patch Update contains -32- new security fixes for Oracle Java SE. 28 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials..."
- http://www.securityt....com/id/1038931
CVE Reference: CVE-2017-10053, CVE-2017-10067, CVE-2017-10074, CVE-2017-10078, CVE-2017-10081, CVE-2017-10086, CVE-2017-10087, CVE-2017-10089, CVE-2017-10090, CVE-2017-10096, CVE-2017-10101, CVE-2017-10102, CVE-2017-10104, CVE-2017-10105, CVE-2017-10107, CVE-2017-10108, CVE-2017-10109, CVE-2017-10110, CVE-2017-10111, CVE-2017-10114, CVE-2017-10115, CVE-2017-10116, CVE-2017-10117, CVE-2017-10118, CVE-2017-10121, CVE-2017-10125, CVE-2017-10135, CVE-2017-10145, CVE-2017-10176, CVE-2017-10193, CVE-2017-10198, CVE-2017-10243
Jul 18 2017
Fix Available: Yes Vendor Confirmed: Yes
Version(s): 6 Update 151, 7 Update 141, 8 Update 131 ...
Impact: A remote user can obtain data on the target system.
A remote user can modify data on the target system.
A remote user can cause denial of service conditions.
A local user can obtain elevated privileges on the target system.
A remote user can gain elevated privileges on the target system.
Solution: The vendor has issued a fix as part of the July 2017 Oracle Critical Patch Update (8 Update 141)...
- https://java.com/en/...irefox_java.xml
Browser(s) Firefox
Java version(s): 7.0, 8.0
"Mozilla offers an Extended Support Release (ESR) version of Firefox specifically for use by organizations who need extended support for mass deployments. Only Mozilla Firefox 52 ESR 32-bit release will continue offering support for the standards-based plugin support technology required to launch Java Applets. To see if you are using an ESR release, check the Firefox menu item (Help -> About) and looking for the "ESR" identifier."
___
... -if- you still need to use Java at all. If not - uninstall it!

Edited by AplusWebMaster, 23 September 2017 - 08:25 AM.