Skip to content
TECH CEO Daily
SaaSLaunch

Oracle releases Java 27 with hybrid post-quantum key exchange for TLS 1.3 on by default

Apps on JDK 27 that use Java's standard TLS APIs can get quantum-resistant TLS handshakes without code changes, but the feature debuts in a short-lived release, not a long-term support version.

By · Editor

· Archive story, added · 4 min read · ✓ Fact-checked

The 60-second brief

  • 1Oracle released Java 27 on September 15, 2026; its TLS 1.3 now prefers a hybrid post-quantum key exchange by default.
  • 2Existing code using standard Java TLS APIs benefits without changes, unless it already selects specific key exchange schemes.
  • 3Java 27 is not a long-term support release; Oracle says it plans comparable capabilities for its long-term support versions.

The news

On September 15, 2026, Oracle (ORCL) released Java 27, adding a hybrid post-quantum key exchange for TLS 1.3 that Java's built-in TLS uses by default, a step toward protecting encrypted traffic from future quantum computers able to break widely used public-key encryption.

The change, known as JEP 527 (JDK Enhancement Proposal 527), combines ML-KEM, a quantum-resistant algorithm added to Java in version 24, with traditional elliptic-curve Diffie-Hellman (ECDHE) key exchange. According to the OpenJDK specification, a hybrid scheme stays secure as long as either of the two algorithms remains unbroken.

Java 27 puts the X25519MLKEM768 hybrid scheme first in its list of preferred key exchange methods. Applications that use Java's standard javax.net.ssl APIs get it without code changes, provided they do not already pick specific schemes and the other side of the connection supports it. Two other hybrid schemes are included but not switched on by default, and the change covers only TLS 1.3.

The target is harvest-now, decrypt-later attacks, in which attackers capture encrypted data now and decrypt it once quantum computers are powerful enough. The JEP notes that large-scale quantum computers capable of breaking RSA and elliptic-curve encryption do not yet exist, but argues the switch is urgent because data captured now can be stored and decrypted later.

Java 27 contains nine JEPs in total, five of which are still in preview or incubator stages, according to InfoQ. Others make compact object headers the default to cut memory use, make G1 the default garbage collector everywhere, and let Java Flight Recorder redact sensitive data. Oracle also released Helidon 27, JavaFX 27 and Oracle Jipher 20, which wraps a FIPS 140-3 validated OpenSSL module and adds support for the ML-KEM and ML-DSA post-quantum algorithms, and highlighted JDK 28 early-access builds, which include Project Valhalla features.

Java 27 is not a long-term support (LTS) release. Oracle's support roadmap gives it Premier Support only until March 2027, while Java 25, the current LTS version, has Premier Support until September 2030. Georges Saab, Oracle's senior vice president for the Java Platform, called Java 27 "a major post-quantum cryptography milestone" and said Oracle is executing on a roadmap to bring comparable capabilities to its LTS releases. The announcement gave no dates for that.

The numbers

JEPs in Java 27
9
JEPs still in preview or incubator (per InfoQ)
5
Oracle Premier Support for Java 27 ends
March 2027
Premier Support for Java 25 LTS ends
September 2030
Next planned LTS release
Java 29, September 2027

Why CEOs should care

For CISOs, this is a low-effort post-quantum step: for code that uses standard Java TLS and does not hard-code key exchange settings, upgrading the runtime is the main change. Start by inventorying which Java versions run where, flag applications that set their own named groups (they will not get the hybrid scheme automatically), and test JDK 27 in staging to confirm that load balancers, proxies and inspection tools handle the new handshake. Teams in FIPS-regulated environments should look at Jipher 20, which Oracle says adds ML-KEM and ML-DSA support.

For CIOs and buyers, the catch is timing. Organizations that standardize on LTS versions do not get this feature yet, and Java 27 loses Oracle Premier Support in March 2027. Ask Oracle, and any other Java vendor you use, for dates when hybrid TLS will reach JDK 25 and JDK 21 updates, and make that part of your quantum-safe migration plan. Oracle's roadmap also says JDK 21 updates starting with the October 2026 Critical Patch Update are planned under the Java SE OTN license rather than a permissive license, so CFOs should confirm licensing terms and weigh an upgrade to JDK 25 against a Java SE subscription.

For boards, the relevant question is how long your encrypted data needs to stay confidential. If the answer is years, the harvest-now risk already applies, and management should be able to show a cryptographic inventory and a timeline for moving key systems to quantum-resistant methods.

The bigger picture

Java is joining a broader shift toward hybrid post-quantum TLS. The JEP says X25519MLKEM768 is the fastest hybrid option and the one most TLS clients are enabling by default, and it builds on a hybrid key exchange framework from the Internet Engineering Task Force's TLS working group. Because Java is so widely used in enterprise software, a default in the runtime can move large volumes of internal and partner traffic without application rewrites, once organizations adopt a version that includes it.

What happened next

The next dates to watch are set by Oracle's own schedules. Its next quarterly Critical Patch Update is due October 20, 2026, the first after the release and the point from which JDK 21 updates are planned to move to the OTN license. InfoQ reported that JDK 28 is expected in March 2027, with a feature freeze in early December 2026; March 2027 is also when Java 27's Premier Support ends.

The more important signal for enterprises will be when Oracle names dates for bringing hybrid TLS to JDK 25 and other LTS releases, which the Java 27 announcement did not include.

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

How this story was made. Researched from primary sources such as company announcements and filings, with the help of technology tools, fact-checked twice, and approved for publication by Hussein Mukhtar.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards · Report an error

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Weekdays, 6 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.

More in SaaS