Oracle released the scheduled critical security updates for its Java SE Runtime Environment software. The update contains 21 new security fixes for multiple versions of Java SE, 18 of which are remotely exploitable without authentication. The update also includes numerous bug fixes.


If Java is still installed on your computer, it is recommended that this update be applied as soon as possible due to the threat posed by a successful attack.

Download Information

Java SE 8u161/8u162

Java™ SE Development Kit 8, Update 161 Release Notes
Java™ SE Development Kit 8, Update 162 Release Notes
Java SE Runtime Environment 8 - Downloads

Java SE 9.0.1 (x64-bit only)

Java™ SE Development Kit 9.0.4 Release Notes
Java SE Runtime Environment 9 - Downloads

  • UNcheck any pre-checked toolbar and/or software options presented with the update. They are not part of the software update and are completely optional. Preferably, see the instructions below on how to handle "Unwanted Extras".
  • Oracle does not plan to migrate desktops from Java 8 to Java 9 through the auto update feature. Therefore, it is strongly recommended that you uninstall JRE 8 prior to updating.
  • Verify your version: Note: The Java version verification page will only work if your browser has NPAPI support. In that case, to check the version, open a cmd window and enter the following (note the space following Java): java -version

Critical Patch Updates and Security Alerts