A Zero-Day notice released by kb.cert.org explains of a new Java 7 zero-day which fails to restrict access to privileged code.
This zero-day is already being utilized in the wild, and is described to be incorporated into exploit kits. Exploit code for this vulnerability is also publicly available. You can find the could on Metasploit’s site.
This exploit could be used on various compromised sites and convincing a user to visit a specially crafted HTML document, a remote attacker may be able to execute arbitrary code on a vulnerable system.
To circumvent any attacks, you can now disable java running in your browser in Oracles new update.