The Polish firm Security Explorations claims in a blog post that it alerted Oracle to a large collection of bugs more than four months ago, and even received confirmation that Oracle had taken note of their findings.
FORBES: Oracle Quietly Releases Fix For Serious Java Security Bug--Months After It Was Reported