LIVE · cybersecurity feed
Live wire
vulnerabilitycritical

Oracle Critical Patch Update, July 2026 Security Update Review

Oracle released its third quarterly edition of this year’s Critical Patch Update. The update received patches for 1449 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products. In this quarterly Oracle Critical Patch Update, Orac

zeroday.news · 10d ago

Oracle has released its third quarterly Critical Patch Update for 2026, addressing a total of 1449 security vulnerabilities across its extensive product portfolio. This update, issued on July 22, 2026, includes patches for both Oracle-developed components and third-party open-source components integrated into Oracle products. Approximately 86% of the patches, or 1235 of the 1449, are for non-Oracle CVEs.

The Oracle E-Business Suite received the highest number of patches in this update, with 410 vulnerabilities addressed, accounting for about 28% of the total. Of these, 45 can be exploited remotely without authentication, and four critical vulnerabilities (CVE-2026-60880, CVE-2026-60773, CVE-2026-62549, and CVE-2026-62546) could lead to remote code execution.

Oracle Fusion Middleware was another heavily impacted product family, receiving 355 security patches. A significant portion, 219 of these vulnerabilities, are remotely exploitable without user credentials. This category includes 154 CVEs with critical severity ratings, also posing a risk of remote code execution.

Oracle Communications products received 168 security patches, with 122 vulnerabilities exploitable over a network without authentication. Thirteen of these CVEs are rated as critical, potentially enabling remote code execution. Oracle PeopleSoft saw 84 security patches, 45 of which are remotely exploitable without authentication, and 17 critical CVEs that could lead to remote code execution.

For Oracle Database products, 72 updates were released. Specifically, Oracle Database Server received 15 new security updates, with a maximum CVSS Base Score of 9.9. Three of these updates apply to client-only deployments. Oracle APEX received three new security updates (max CVSS 5.5), and Oracle Autonomous Health Framework received four (max CVSS 8.1). Oracle Essbase received one update (CVSS 4.8), and Oracle Global Lifecycle Management also received one (CVSS 8.1).

Oracle GoldenGate received 27 new security updates, with a maximum CVSS Base Score of 9.1. Oracle NoSQL Database and Oracle Spatial Studio each received one new security update. Oracle SQL Developer received five new security updates, all of which are remotely exploitable without authentication, though their maximum CVSS score is not yet verified. Oracle TimesTen In-Memory Database received 14 new security updates, with four being remotely exploitable without authentication. Oracle Graph Server and Client did not receive new security updates but were provided with third-party patches.

Oracle MySQL received 54 security patches, with nine vulnerabilities exploitable over a network without user credentials. Notably, none of the CVEs in Oracle MySQL were assigned a critical severity rating in this update.

Other product families covered in this Critical Patch Update include Oracle Commerce, Oracle Supply Chain, Oracle Financial Services Applications, Oracle Analytics, Oracle Application Testing Suite, Oracle Construction and Engineering (Primavera), Oracle Enterprise Manager, Oracle Food and Beverage Applications (Hospitality Simphony), Oracle Health Sciences / HealthCare Applications, Oracle Hospitality (Cruise SPMS), Oracle Java SE, Oracle JD Edwards, Oracle Retail Applications, Oracle Systems (Solaris), and Oracle Virtualization (VM VirtualBox).

vulnerabilitypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.