Oracle has released a record 1,449 security patches as part of its quarterly update cycle, a number that security experts suggest reflects a growing trend in the industry driven by the increasing use of artificial intelligence in vulnerability detection. This substantial volume of fixes spans Oracle's extensive product portfolio.
The company's internal push to leverage AI for identifying vulnerabilities, announced in April, is believed to be a contributing factor to the record number of patches. Of the total, only 64 vulnerabilities were credited to external researchers, indicating that the majority of bug discovery was conducted internally, likely with AI assistance.
Security specialists emphasize that the large number of patches primarily highlights the vast scale of modern software ecosystems and the industry's move toward aggressive, automated security scanning. The main concern, they note, is the significant operational burden placed on enterprise IT teams who must prioritize and apply these updates without disrupting business operations.
This increase in security updates is not unique to Oracle. Microsoft has also seen a substantial rise in its monthly Patch Tuesday updates, with July's 622 CVEs surpassing June's 206, which was previously a record. Microsoft had previously warned that AI's role in vulnerability detection would lead to a higher volume of security updates. Both Oracle and Microsoft encourage customers to utilize automated patching tools and support resources to manage the growing workload.
In response to the evolving threat landscape, Oracle began supplementing its quarterly updates in May 2026 with monthly Critical Security Patch Updates (CSPUs) for the most critical vulnerabilities. These smaller, more frequent batches are designed to allow customers to apply urgent fixes more quickly, while cumulative updates continue through the established quarterly cycles.
Among the 1,449 patches, ten carried a maximum CVSS score of 10.0, all affecting Oracle Fusion Middleware. The Dutch NCSC highlighted two of these as particularly dangerous: CVE-2026-47056 and CVE-2026-60217. Both are described as easily exploitable by unauthenticated attackers. CVE-2026-47056 allows an attacker to take over Oracle Data Integrator via HTTP, while CVE-2026-60217 enables the same against Oracle Coherence over TCP. The NCSC-NL urged immediate application of these updates due to the high risk of exploitation, which could lead to malicious code execution, sensitive data exposure, or complete system takeover.
Additionally, two high-rated vulnerabilities affecting Oracle Database Server were noted: CVE-2026-61211 (CVSS 9.9) and CVE-2026-47040 (CVSS 9.1). CVE-2026-47040, found in Oracle Net Service, is an unauthenticated vulnerability that could grant attackers access to stored data and potentially crash the service. CVE-2026-61211, within the DBMS_CLOUD package, carries the highest score in the database batch, potentially allowing a low-privilege attacker to achieve remote code execution and takeover of Oracle's RDBMS, with downstream implications for other products utilizing the database.






