Oracle addresses 1235 CVEs in its third quarterly update of 2026 with 1449 patches, including 261 critical updates. Key Takeaways The third Critical Patch Update (CPU) for 2026 contains fixes for 1235 unique CVEs in 1449 security updates, the largest CPU release. 261 issues (18% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches

Oracle released its July 2026 Critical Patch Update (CPU), addressing 1,235 unique Common Vulnerabilities and Exposures (CVEs) across 32 product families. This quarterly update, the third for 2026, includes a total of 1,449 security patches, making it the largest CPU release to date.
Of the 1,449 patches, 261 (18%) were assigned a critical severity rating, impacting 228 distinct CVEs. High severity patches constituted the majority at 763, covering 613 CVEs, while medium severity patches accounted for 358 fixes across 332 CVEs. Additionally, 67 low severity patches were released for 62 CVEs.
The Oracle E-Business Suite product family received the highest number of patches, with 410 updates, representing 28.3% of the total. Following closely was Oracle Fusion Middleware, with 355 patches, making up 24.5% of the update.
Many of the addressed vulnerabilities could be exploited remotely without authentication. Oracle Fusion Middleware had the most such vulnerabilities, with 219. Oracle Communications followed with 122, and Oracle E-Business Suite had 45. Other product families with significant numbers of remotely exploitable vulnerabilities included Oracle PeopleSoft (45), Oracle Siebel CRM (32), Oracle Commerce (26), and Oracle Financial Services Applications (26).
Other product families receiving patches include Oracle MySQL (54 patches, 9 remote exploits without authentication), Oracle Supply Chain (39 patches, 16 remote exploits), Oracle GoldenGate (27 patches, 9 remote exploits), Oracle Enterprise Manager (27 patches, 13 remote exploits), Oracle Retail Applications (22 patches, 20 remote exploits), and Oracle JD Edwards (20 patches, 4 remote exploits).
Oracle Java SE received 19 patches, 17 of which were remotely exploitable without authentication. Oracle Database Server had 15 patches, with 6 remote exploits. Oracle Virtualization received 16 patches, none of which were remotely exploitable without authentication.
Customers are strongly advised to apply all relevant patches included in this CPU to mitigate potential risks. Oracle has provided a detailed advisory and risk matrices for further information.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]