Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Oracle July 2026 Critical Patch Update Addresses 1235 CVEs

0
Critical
Published: 07/21/2026 (07/21/2026, 21:07:46 UTC)
Source: Tenable Research

Description

Oracle addresses 1235 CVEs in its third quarterly update of 2026 with 1449 patches, including 261 critical updates. Key Takeaways The third Critical Patch Update (CPU) for 2026 contains fixes for 1235 unique CVEs in 1449 security updates, the largest CPU release. 261 issues (18% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at 410, accounting for 28.3% of all patches Background On July 21, Oracle released its Critical Patch Update (CPU) for July 2026 , the third quarterly update of the year. This CPU contains fixes for 1235 unique CVEs in 1449 security updates across 32 Oracle product families. Out of the 1449 security updates published this quarter, 18% of patches were assigned a critical severity. High severity patches accounted for the bulk of security patches at 52.7%, followed by medium severity patches at 24.7%. This quarter's update includes 261 critical patches across 228 CVEs. Severity Issues Patched CVEs Critical 261 228 High 763 613 Medium 358 332 Low 67 62 Total 1449 1235 Analysis This quarter, the Oracle E-Business Suite product family contained the highest number of patches at 410, accounting for 28.3% of the total patches, followed by Oracle Fusion Middleware at 355 patches, which accounted for 24.5% of the total patches. A full breakdown of the patches for this quarter can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication. Oracle Product Family Number of Patches Remote Exploit without Auth Oracle E-Business Suite 410 45 Oracle Fusion Middleware 355 219 Oracle Communications 168 122 Oracle PeopleSoft 84 45 Oracle MySQL 54 9 Oracle Siebel CRM 45 32 Oracle Commerce 39 26 Oracle Supply Chain 39 16 Oracle Financial Services Applications 31 26 Oracle GoldenGate 27 9 Oracle Enterprise Manager 27 13 Oracle Retail Applications 22 20 Oracle JD Edwards 20 4 Oracle Java SE 19 17 Oracle Virtualization 16 0 Oracle Database Server 15 6 Oracle TimesTen In-Memory Database 14 4 Oracle Utilities Applications 14 10 Oracle Construction and Engineering 7 7 Oracle Analytics 7 5 Oracle Systems 6 0 Oracle SQL Developer 5 5 Oracle Autonomous Health Framework 4 3 Oracle Application Testing Suite 4 4 Oracle Food and Beverage Applications 4 4 Oracle HealthCare Applications 4 4 Oracle APEX 3 2 Oracle Hospitality Applications 2 2 Oracle Essbase 1 1 Oracle Global Lifecycle Management 1 1 Oracle NoSQL Database 1 1 Oracle Spatial Studio 1 1 Solution Customers are advised to apply all relevant patches in this quarter's CPU. Please refer to the July 2026 advisory for full details. Identifying affected systems A list of Tenable plugins to identify these vulnerabilities will appear here as they're released. This link uses a search filter to ensure that all matching plugin coverage will appear as it is released. Get more information Oracle Critical Patch Update Advisory - July 2026 Oracle July 2026 Critical Patch Update Risk Matrices Oracle Advisory to CVE Map Join Tenable's Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats. Learn more about Tenable One , the Exposure Management Platform for the modern attack surface.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/15/2026, 05:07:23 UTC

Technical Analysis

The July 2026 Oracle CPU fixes 1235 unique vulnerabilities through 1449 patches, with 261 critical severity issues affecting multiple Oracle product families. Oracle E-Business Suite and Fusion Middleware are the most heavily impacted, with many vulnerabilities exploitable remotely without authentication. The update represents the largest quarterly CPU release by Oracle, addressing a broad range of security flaws across their software portfolio.

Potential Impact

The vulnerabilities patched include critical issues that could allow remote exploitation without authentication, potentially leading to unauthorized access, data compromise, or disruption of services in affected Oracle products. The widespread nature of the patches across many product families indicates a broad attack surface if unpatched. The critical severity of many issues underscores the importance of timely remediation.

Mitigation Recommendations

Oracle customers should promptly apply all relevant patches included in the July 2026 CPU to mitigate the addressed vulnerabilities. No vendor advisory indicates that any issues are already mitigated or require no action. Patch status is confirmed as available through this official CPU release.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.tenable.com/blog/oracle-july-2026-critical-patch-update-addresses-1235-cves","fetched":true,"fetchedAt":"2026-07-22T01:54:56.179Z","wordCount":2269}
Exploit Sophistication
7
Weaponization Potential
8
Stealth Capability
6
Ai Analysis Type
exploit-specialized
Classification
{"confidence":0.95,"severitySource":"stated","classifier":"rss-v2"}

Threat ID: 6a6022f19c2644c7f826116b

Added to database: 07/22/2026, 01:54:57 UTC

Last enriched: 08/15/2026, 05:07:23 UTC

Last updated: 09/05/2026, 00:13:25 UTC

Views: 483

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses