Oracle has released its third quarterly Critical Patch Update for 2026, addressing a total of 1449 security vulnerabilities across its extensive product portfolio. This update, issued on July 22, 2026, includes patches for both Oracle-developed components and third-party open-source components integrated into Oracle products. Approximately 86% of the patches, or 1235 of the 1449, are for non-Oracle CVEs.
The Oracle E-Business Suite received the highest number of patches in this update, with 410 vulnerabilities addressed, accounting for about 28% of the total. Of these, 45 can be exploited remotely without authentication, and four critical vulnerabilities (CVE-2026-60880, CVE-2026-60773, CVE-2026-62549, and CVE-2026-62546) could lead to remote code execution.
Oracle Fusion Middleware was another heavily impacted product family, receiving 355 security patches. A significant portion, 219 of these vulnerabilities, are remotely exploitable without user credentials. This category includes 154 CVEs with critical severity ratings, also posing a risk of remote code execution.
Oracle Communications products received 168 security patches, with 122 vulnerabilities exploitable over a network without authentication. Thirteen of these CVEs are rated as critical, potentially enabling remote code execution. Oracle PeopleSoft saw 84 security patches, 45 of which are remotely exploitable without authentication, and 17 critical CVEs that could lead to remote code execution.
For Oracle Database products, 72 updates were released. Specifically, Oracle Database Server received 15 new security updates, with a maximum CVSS Base Score of 9.9. Three of these updates apply to client-only deployments. Oracle APEX received three new security updates (max CVSS 5.5), and Oracle Autonomous Health Framework received four (max CVSS 8.1). Oracle Essbase received one update (CVSS 4.8), and Oracle Global Lifecycle Management also received one (CVSS 8.1).
Oracle GoldenGate received 27 new security updates, with a maximum CVSS Base Score of 9.1. Oracle NoSQL Database and Oracle Spatial Studio each received one new security update. Oracle SQL Developer received five new security updates, all of which are remotely exploitable without authentication, though their maximum CVSS score is not yet verified. Oracle TimesTen In-Memory Database received 14 new security updates, with four being remotely exploitable without authentication. Oracle Graph Server and Client did not receive new security updates but were provided with third-party patches.
Oracle MySQL received 54 security patches, with nine vulnerabilities exploitable over a network without user credentials. Notably, none of the CVEs in Oracle MySQL were assigned a critical severity rating in this update.
Other product families covered in this Critical Patch Update include Oracle Commerce, Oracle Supply Chain, Oracle Financial Services Applications, Oracle Analytics, Oracle Application Testing Suite, Oracle Construction and Engineering (Primavera), Oracle Enterprise Manager, Oracle Food and Beverage Applications (Hospitality Simphony), Oracle Health Sciences / HealthCare Applications, Oracle Hospitality (Cruise SPMS), Oracle Java SE, Oracle JD Edwards, Oracle Retail Applications, Oracle Systems (Solaris), and Oracle Virtualization (VM VirtualBox).






