Amazon Corretto August 2026 Critical Security Patch Updates
Amazon Web Services released critical security patches for multiple Amazon Corretto OpenJDK versions on August 18, 2026, addressing vulnerabilities in production-ready distributions.
Amazon Web Services issued critical security patch updates for Amazon Corretto Long-Term Support and Feature Release versions of OpenJDK on August 18, 2026. The updates cover Corretto 26.0.2.11.1, 25.0.4.8.1, 21.0.12.9.1, 17.0.20.10.1, 11.0.32.10.1, and 8u504, addressing identified security vulnerabilities. Users are advised to apply these patches promptly to mitigate potential risks. The updates are available for download from the Corretto homepage or via configured package repositories.
The patches apply to Amazon Corretto, a no-cost, multi-platform distribution of OpenJDK maintained by AWS for production use. Corretto versions 26, 25, 21, 17, 11, and 8 are affected, with updates provided for both Long-Term Support and Feature Release branches. Organizations using these versions should review the patch notes and update their environments to the latest releases to ensure security compliance.
AWS recommends configuring Corretto package repositories on Linux systems to streamline future updates. Users can enable Apt, Yum, or Apk repositories to receive automatic security patches. This approach simplifies maintenance and ensures timely delivery of critical fixes without manual intervention. The repositories support multiple Linux distributions, including Debian, Ubuntu, Amazon Linux, and Alpine.
The critical security patches address vulnerabilities that could expose systems to exploitation if left unpatched. AWS has not disclosed specific threat details but emphasizes the importance of immediate application of these updates. Users should prioritize testing and deploying the patches in staging environments before full production rollout to avoid disruptions.