Oracle Patches 1,449 Security Flaws Across 334 Enterprise Products
Oracle has released its July 2026 Critical Patch Update with 1,449 new security patches covering 1,434 distinct CVEs across 334 products. The release addresses vulnerabilities in Oracle Database, Fusion Middleware, Java, MySQL, E-Business Suite, Communications products, and other enterprise platforms.
The official Oracle July 2026 Critical Patch Update advisory includes numerous vulnerabilities that attackers can exploit remotely without authentication. Several Fusion Middleware flaws carry the maximum CVSS score of 10.0 and could expose internet-facing enterprise servers to serious compromise.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
Oracle calls the update its largest security release to date. The company’s July security update announcement attributes the record size to wider product coverage, faster security engineering, AI-assisted vulnerability discovery, and the expanding scope of quarterly updates.
Oracle July 2026 Security Update: Key Figures
| Category | Oracle figure |
|---|---|
| New security patches | 1,449 |
| Distinct CVEs addressed | 1,434 |
| Oracle products covered | 334 |
| Fusion Middleware patches | 355, plus third-party component fixes |
| Fusion Middleware flaws remotely exploitable without authentication | 219 |
| Oracle Java SE patches | 19, plus third-party component fixes |
| Java SE flaws remotely exploitable without authentication | 17 |
Oracle released the CPU on July 21, 2026. It covers more than 30 product families, including business applications, databases, middleware, development tools, cloud infrastructure components, communications platforms, and industry-specific software.
A Tenable analysis of the update counted 1,235 unique CVEs across 1,449 security updates. Tenable classified 18% of the patches as critical severity, 52.7% as high severity, and 24.7% as medium severity.
Oracle reports 1,434 distinct CVEs in its own announcement. The difference likely comes from how each organization counts vulnerabilities, product mappings, and third-party component issues. Administrators should use Oracle’s product risk matrices and patch availability documents when identifying affected systems.
Critical Fusion Middleware Flaws Allow Remote Attacks
Oracle Fusion Middleware received 355 new security patches, along with additional fixes for third-party components. Oracle says attackers can exploit 219 of these vulnerabilities over a network without supplying user credentials.
The official Oracle risk matrices list several Fusion Middleware vulnerabilities with CVSS scores of 10.0. They affect components such as Oracle Coherence, Data Integrator, HTTP Server, Unified Directory, WebCenter Content, and Service Delivery Platform Messaging Enabler.
These flaws use network-accessible protocols such as HTTP, LDAP, SOAP, and TCP. Organizations that expose affected services to the internet should treat them as urgent patching priorities.
| CVE | Affected component | Protocol | CVSS score |
|---|---|---|---|
| CVE-2026-60217 | Oracle Coherence Core | TCP | 10.0 |
| CVE-2026-47056 | Oracle Data Integrator REST Service | HTTP | 10.0 |
| CVE-2026-60365 | Oracle HTTP Server and WebLogic proxy components | HTTP | 10.0 |
| CVE-2026-60366 | Oracle Platform Security for Java | HTTP | 10.0 |
| CVE-2026-60360 | Oracle Unified Directory | LDAP | 10.0 |
| CVE-2026-60644 | Oracle WebCenter Content | HTTP | 10.0 |
| CVE-2026-60389 | Service Delivery Platform Messaging Enabler | HTTP | 10.0 |
| CVE-2026-60379 | Service Delivery Platform Messaging Enabler | SOAP | 10.0 |
Database, Java, MySQL, and Business Applications Need Updates
The release covers Oracle Database Server and related technologies, including APEX, GoldenGate, SQL Developer, Spatial Studio, TimesTen In-Memory Database, and Autonomous Health Framework.
Oracle Java SE received 19 security patches, with 17 vulnerabilities open to remote exploitation without authentication. Administrators should review their installed Java versions, dependent applications, and embedded Java runtimes instead of checking only standalone installations.
Oracle also published fixes for MySQL Server, MySQL Cluster, MySQL Router, and MySQL Connectors. The wider CPU covers E-Business Suite, JD Edwards, PeopleSoft, Siebel CRM, Oracle Retail, Financial Services applications, Oracle Communications, and multiple cloud-native products.
- Oracle Database Server and associated management tools
- Oracle Fusion Middleware and WebLogic-related components
- Oracle Java SE and GraalVM products
- MySQL Server, Cluster, Router, and Connectors
- Oracle E-Business Suite and JD Edwards EnterpriseOne
- Oracle PeopleSoft and Siebel CRM
- Oracle Communications and Cloud Native Core products
- Oracle Financial Services and industry applications
- Oracle Linux, Systems, and Virtualization products
AI-Assisted Research Increased the Number of Findings
Oracle says AI-powered security research contributed to the scale of the July release. In an earlier report about accelerating vulnerability detection and response, the company confirmed that its security teams had gained access to Anthropic’s Claude Mythos Preview and advanced OpenAI models through Trusted Access for Cyber.
Oracle uses these systems alongside its existing security tools to analyze software, services, Oracle Health technology, and open-source components embedded in its products. The company says this process helps its teams identify risks and develop mitigations sooner.
However, Oracle has not publicly identified which individual July CVEs came from each AI model. The company’s AI security engineering report describes the broader program but does not provide a CVE-by-CVE attribution list.
Oracle Moves Customers Toward Monthly Patching
Oracle now supplements its quarterly CPUs with smaller monthly Critical Security Patch Updates. The company explains in its Critical Security Patch Update advisory that CSPUs deliver targeted, high-priority fixes in a format designed for faster deployment.
The quarterly CPU remains cumulative and covers a broad range of products. Monthly CSPUs address urgent issues between quarterly releases, including vulnerabilities in Oracle code and third-party components.
Oracle recommends that customers adopt a monthly security patching cycle. Its June 2026 CSPU documentation also warns that older, unsupported releases may contain the same vulnerabilities without receiving tested patches.
| Update type | Release approach | Purpose |
|---|---|---|
| Critical Patch Update | Quarterly cumulative release | Broad security coverage across Oracle product families |
| Critical Security Patch Update | Monthly targeted release | Smaller collection of high-priority fixes |
| Security Alert | Released when necessary | Urgent response to specific high-risk vulnerabilities |
Some Included Vulnerabilities Face Active Exploitation
Oracle regularly receives reports of attackers targeting vulnerabilities for which patches already exist. The company says attackers have succeeded in some cases because customers failed to install available security updates.
A Hong Kong Government CERT alert says researchers have reported active exploitation involving CVE-2021-22555 and CVE-2026-31431. The alert also lists several vulnerabilities with publicly available proof-of-concept code.
This does not mean attackers currently exploit every vulnerability in the July CPU. However, the government security warning reinforces the need to prioritize exposed systems, especially when public exploit code or known attacks already exist.
How Security Teams Should Prioritize the Oracle Patches
Organizations should begin by creating an accurate inventory of Oracle products, versions, installed components, and internet-facing services. They should then match those systems against Oracle’s risk matrices and patch availability documents.
Security teams should prioritize vulnerabilities that allow unauthenticated network attacks, carry critical CVSS scores, affect high-privilege services, or expose sensitive business data. They should also consider the importance of each system and the controls protecting it.
The Oracle security release notice urges customers to install the update promptly and move to a monthly patching schedule. Unsupported products require upgrades because Oracle does not test or provide CPU patches for versions outside Premier Support or Extended Support.
- Identify all Oracle products and confirm their exact versions.
- Locate systems accessible from the internet or untrusted networks.
- Prioritize unauthenticated remote vulnerabilities and CVSS 10.0 flaws.
- Test patches in a representative non-production environment.
- Back up configurations, databases, and application data before deployment.
- Patch database, middleware, and application dependencies together when required.
- Confirm that the update succeeded and restart affected services.
- Run vulnerability scans to detect missing or incomplete patches.
- Review logs for signs of exploitation before and after patching.
- Upgrade unsupported Oracle releases that cannot receive current fixes.
Compensating Controls Can Reduce Risk During Testing
Some organizations cannot update critical Oracle systems immediately because patches require application testing, planned downtime, or coordination with third-party vendors. Temporary controls can reduce exposure while teams complete that work.
Oracle recommends blocking network protocols that an attack requires or removing unnecessary privileges and package access. These measures can disrupt application functions, so administrators should test every change before using it in production.
Network segmentation, access-control lists, web application firewalls, restricted management interfaces, and stronger monitoring can provide additional protection. Organizations should treat these controls as temporary safeguards because they do not correct the underlying vulnerabilities.
- Remove unnecessary internet access from Oracle management interfaces.
- Restrict HTTP, LDAP, SOAP, TCP, and other affected protocols by source network.
- Place database and middleware servers behind segmented application tiers.
- Limit administrative access to dedicated management networks.
- Monitor unusual requests, authentication failures, and unexpected process activity.
- Apply virtual patching rules where supported by security gateways.
- Set a firm deadline for replacing temporary controls with vendor patches.
Oracle’s July 2026 CPU requires more than a routine patch deployment. Its size, the number of remotely exploitable flaws, and the presence of several CVSS 10.0 vulnerabilities make rapid asset identification and risk-based patching essential for enterprise administrators.
FAQ
Oracle says the July 2026 Critical Patch Update includes 1,449 security patches covering 1,434 distinct CVEs across 334 products. Tenable reported 1,235 unique CVEs using a different counting method.
Yes. Oracle lists many vulnerabilities that attackers can exploit over a network without credentials. Fusion Middleware alone received patches for 219 vulnerabilities that meet this condition.
The update covers Oracle Database, Fusion Middleware, Java SE, MySQL, E-Business Suite, JD Edwards, PeopleSoft, Communications products, Financial Services applications, and many other enterprise platforms.
Oracle says AI-powered identification contributed to the size of the release. Its security teams use frontier models from Anthropic and OpenAI, but Oracle has not published a list linking individual CVEs to specific models.
Security authorities have reported active exploitation involving at least two vulnerabilities associated with the July advisory. Public proof-of-concept code also exists for several other flaws, although no evidence shows active exploitation of every patched vulnerability.
Oracle recommends applying the patches without delay. Administrators should prioritize internet-facing systems, unauthenticated remote vulnerabilities, CVSS 10.0 flaws, and products that handle sensitive or business-critical data.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages