LIVE · cybersecurity feed
Live wire
vulnerabilitycritical

Oracle July 2026 Critical Patch Update Addresses 1235 CVEs

Oracle addresses 1235 CVEs in its third quarterly update of 2026 with 1449 patches, including 261 critical updates. Key Takeaways The third Critical Patch Update (CPU) for 2026 contains fixes for 1235 unique CVEs in 1449 security updates, the largest CPU release. 261 issues (18% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches

zeroday.news · 11d ago

Oracle released its July 2026 Critical Patch Update (CPU), addressing 1,235 unique Common Vulnerabilities and Exposures (CVEs) across 32 product families. This quarterly update, the third for 2026, includes a total of 1,449 security patches, making it the largest CPU release to date.

Of the 1,449 patches, 261 (18%) were assigned a critical severity rating, impacting 228 distinct CVEs. High severity patches constituted the majority at 763, covering 613 CVEs, while medium severity patches accounted for 358 fixes across 332 CVEs. Additionally, 67 low severity patches were released for 62 CVEs.

The Oracle E-Business Suite product family received the highest number of patches, with 410 updates, representing 28.3% of the total. Following closely was Oracle Fusion Middleware, with 355 patches, making up 24.5% of the update.

Many of the addressed vulnerabilities could be exploited remotely without authentication. Oracle Fusion Middleware had the most such vulnerabilities, with 219. Oracle Communications followed with 122, and Oracle E-Business Suite had 45. Other product families with significant numbers of remotely exploitable vulnerabilities included Oracle PeopleSoft (45), Oracle Siebel CRM (32), Oracle Commerce (26), and Oracle Financial Services Applications (26).

Other product families receiving patches include Oracle MySQL (54 patches, 9 remote exploits without authentication), Oracle Supply Chain (39 patches, 16 remote exploits), Oracle GoldenGate (27 patches, 9 remote exploits), Oracle Enterprise Manager (27 patches, 13 remote exploits), Oracle Retail Applications (22 patches, 20 remote exploits), and Oracle JD Edwards (20 patches, 4 remote exploits).

Oracle Java SE received 19 patches, 17 of which were remotely exploitable without authentication. Oracle Database Server had 15 patches, with 6 remote exploits. Oracle Virtualization received 16 patches, none of which were remotely exploitable without authentication.

Customers are strongly advised to apply all relevant patches included in this CPU to mitigate potential risks. Oracle has provided a detailed advisory and risk matrices for further information.

vulnerabilitypatchhealthcarefinance
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]

breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.