Oracle released its third quarterly edition of this year’s Critical Patch Update. The update received patches for 1449 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products. In this quarterly Oracle Critical Patch Update, Orac

Oracle has released its third quarterly Critical Patch Update for 2026, addressing a total of 1449 security vulnerabilities across its extensive product portfolio. This update, issued on July 22, 2026, includes patches for both Oracle-developed components and third-party open-source components integrated into Oracle products. Approximately 86% of the patches, or 1235 of the 1449, are for non-Oracle CVEs.
The Oracle E-Business Suite received the highest number of patches in this update, with 410 vulnerabilities addressed, accounting for about 28% of the total. Of these, 45 can be exploited remotely without authentication, and four critical vulnerabilities (CVE-2026-60880, CVE-2026-60773, CVE-2026-62549, and CVE-2026-62546) could lead to remote code execution.
Oracle Fusion Middleware was another heavily impacted product family, receiving 355 security patches. A significant portion, 219 of these vulnerabilities, are remotely exploitable without user credentials. This category includes 154 CVEs with critical severity ratings, also posing a risk of remote code execution.
Oracle Communications products received 168 security patches, with 122 vulnerabilities exploitable over a network without authentication. Thirteen of these CVEs are rated as critical, potentially enabling remote code execution. Oracle PeopleSoft saw 84 security patches, 45 of which are remotely exploitable without authentication, and 17 critical CVEs that could lead to remote code execution.
For Oracle Database products, 72 updates were released. Specifically, Oracle Database Server received 15 new security updates, with a maximum CVSS Base Score of 9.9. Three of these updates apply to client-only deployments. Oracle APEX received three new security updates (max CVSS 5.5), and Oracle Autonomous Health Framework received four (max CVSS 8.1). Oracle Essbase received one update (CVSS 4.8), and Oracle Global Lifecycle Management also received one (CVSS 8.1).
Oracle GoldenGate received 27 new security updates, with a maximum CVSS Base Score of 9.1. Oracle NoSQL Database and Oracle Spatial Studio each received one new security update. Oracle SQL Developer received five new security updates, all of which are remotely exploitable without authentication, though their maximum CVSS score is not yet verified. Oracle TimesTen In-Memory Database received 14 new security updates, with four being remotely exploitable without authentication. Oracle Graph Server and Client did not receive new security updates but were provided with third-party patches.
Oracle MySQL received 54 security patches, with nine vulnerabilities exploitable over a network without user credentials. Notably, none of the CVEs in Oracle MySQL were assigned a critical severity rating in this update.
Other product families covered in this Critical Patch Update include Oracle Commerce, Oracle Supply Chain, Oracle Financial Services Applications, Oracle Analytics, Oracle Application Testing Suite, Oracle Construction and Engineering (Primavera), Oracle Enterprise Manager, Oracle Food and Beverage Applications (Hospitality Simphony), Oracle Health Sciences / HealthCare Applications, Oracle Hospitality (Cruise SPMS), Oracle Java SE, Oracle JD Edwards, Oracle Retail Applications, Oracle Systems (Solaris), and Oracle Virtualization (VM VirtualBox).
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.