Oracle’s latest Java update fixes 25 vulnerabilities in the aging platform, including one that’s already being exploited in attacks. The most high-risk vulnerability fixed in this Java update is known as CVE-2015-2590 and had zero-day status until this update. Java is still widely used for Web-based applications in business environments, it’s rarely seen on consumer-oriented websites today. Many users don’t need the Java browser plug-in, which is the target of the majority of Java exploits.”]

