Oracle released its July 2026 Critical Patch Update (CPU), addressing 1,235 unique Common Vulnerabilities and Exposures (CVEs) across 32 product families. This quarterly update, the third for 2026, includes a total of 1,449 security patches, making it the largest CPU release to date.
Of the 1,449 patches, 261 (18%) were assigned a critical severity rating, impacting 228 distinct CVEs. High severity patches constituted the majority at 763, covering 613 CVEs, while medium severity patches accounted for 358 fixes across 332 CVEs. Additionally, 67 low severity patches were released for 62 CVEs.
The Oracle E-Business Suite product family received the highest number of patches, with 410 updates, representing 28.3% of the total. Following closely was Oracle Fusion Middleware, with 355 patches, making up 24.5% of the update.
Many of the addressed vulnerabilities could be exploited remotely without authentication. Oracle Fusion Middleware had the most such vulnerabilities, with 219. Oracle Communications followed with 122, and Oracle E-Business Suite had 45. Other product families with significant numbers of remotely exploitable vulnerabilities included Oracle PeopleSoft (45), Oracle Siebel CRM (32), Oracle Commerce (26), and Oracle Financial Services Applications (26).
Other product families receiving patches include Oracle MySQL (54 patches, 9 remote exploits without authentication), Oracle Supply Chain (39 patches, 16 remote exploits), Oracle GoldenGate (27 patches, 9 remote exploits), Oracle Enterprise Manager (27 patches, 13 remote exploits), Oracle Retail Applications (22 patches, 20 remote exploits), and Oracle JD Edwards (20 patches, 4 remote exploits).
Oracle Java SE received 19 patches, 17 of which were remotely exploitable without authentication. Oracle Database Server had 15 patches, with 6 remote exploits. Oracle Virtualization received 16 patches, none of which were remotely exploitable without authentication.
Customers are strongly advised to apply all relevant patches included in this CPU to mitigate potential risks. Oracle has provided a detailed advisory and risk matrices for further information.






