A critical vulnerability in the 2D component that allowed unauthenticated network attacks. CVE-2015-4741:

Java 7 Update 80 (7u80), released in April 2015, was the for Java SE 7. Because it is now a legacy version that has reached its end of life (EOL), it lacks a decade's worth of critical security patches, making it a high-risk environment for modern systems. 1. The "Final Patch" Paradox

have been discovered for Java 7 since its free public updates ended. Common risks include: Azul Systems Remote Code Execution (RCE)

Java 7 update 80 lacks critical security hardening that later Java versions have: