Patch Java now, says Oracle.

Malicious web page could achieve remote PC takeover without authentication

Oracle is urging Java users to upgrade, ASAP, to crimp a very nasty bug in the desktop and browser plug-in versions of the software.

Labelled CVE-2016-0636, the flaw scored a 9.3 on the Common Vulnerability Scoring System bug severity rating.

That high score comes about because the flaw means attackers “can impact the availability, integrity, and confidentiality of the user’s system.” Worse still, an attacker can do that remotely, without authentication.

