Oracle May 2026 Critical Security Patch Update Addresses 35 CVEs
Oracle addresses 35 CVEs in its May 2026 Critical Security Patch Update with 35 patches, including 11 critical updates. Key Takeaways The May 2026 Critical Security Patch Update (CSPU) contains fixes for 35 unique CVEs in 35 security updates 11 issues (31.4% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at 12, accounting for 34.3% of all patches Background On May 28, Oracle released its Critical Security Patch Update (CSPU) for May 2026 . Beginning in May 2026, Oracle introduced CSPUs as a monthly release cycle that sits between the larger quarterly Critical Patch Updates (CPUs), addressing a focused set of high-severity issues on a faster cadence. This CSPU contains fixes for 35 unique CVEs in 35 security updates across 5 Oracle product families. Out of the 35 security updates published, 31.4% of patches were assigned a critical severity. High severity patches accounted for the bulk of security patches at 51.4%, followed by critical severity patches at 31.4%. This month's update includes 11 critical patches across 11 CVEs. Severity Issues Patched CVEs Critical 11 11 High 18 18 Medium 6 6 Low 0 0 Total 35 35 Analysis This month's update saw the Oracle E-Business Suite product family contain the highest number of patches at 12, accounting for 34.3% of the total patches, followed by Oracle REST Data Services at 11 patches, which accounted for 31.4% of the total patches. A full breakdown of the patches for this CSPU can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication. Oracle Product Family Number of Patches Remote Exploit without Auth Oracle E-Business Suite 12 3 Oracle REST Data Services 11 7 Oracle Communications 8 4 Oracle Database Server 3 3 Oracle Hospitality Applications 1 1 Solution Customers are advised to apply all relevant patches in this CSPU. Please refer to the May 2026 advisory for full details. Identifying affected systems A list of Tenable plugins to identify these vulnerabilities will appear here as they're released. This link uses a search filter to ensure that all matching plugin coverage will appear as it is released. Get more information Oracle Critical Security Patch Update Advisory - May 2026 Oracle May 2026 Critical Security Patch Update Risk Matrices Oracle Advisory to CVE Map Join Tenable's Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats. Learn more about Tenable One , the Exposure Management Platform for the modern attack surface.
AI Analysis
Technical Summary
The May 2026 Oracle CSPU contains 35 security updates fixing 35 unique CVEs, with 11 critical and 18 high severity issues. The patches cover five Oracle product families: Oracle E-Business Suite (12 patches), Oracle REST Data Services (11 patches), Oracle Communications (8 patches), Oracle Database Server (3 patches), and Oracle Hospitality Applications (1 patch). Multiple vulnerabilities allow remote exploitation without authentication, increasing the risk of compromise. This CSPU is part of Oracle's new monthly patch cycle introduced in May 2026 to address high-severity issues more rapidly.
Potential Impact
The vulnerabilities addressed include critical and high severity issues, some of which can be exploited remotely without authentication, potentially allowing attackers to compromise affected Oracle products. The Oracle E-Business Suite and Oracle REST Data Services are notably impacted with the highest number of patches. Exploitation could lead to unauthorized access, data breaches, or disruption of services depending on the specific vulnerabilities patched.
Mitigation Recommendations
Oracle has released official patches for all 35 vulnerabilities in this May 2026 CSPU. Customers should promptly apply all relevant patches to affected Oracle products as detailed in the official advisory. Since this is a traditional on-premises software update, remediation requires manual patch application by customers. Patch status is confirmed as official-fix. No indication of automatic or cloud service patching is provided.
Oracle May 2026 Critical Security Patch Update Addresses 35 CVEs
Description
Oracle addresses 35 CVEs in its May 2026 Critical Security Patch Update with 35 patches, including 11 critical updates. Key Takeaways The May 2026 Critical Security Patch Update (CSPU) contains fixes for 35 unique CVEs in 35 security updates 11 issues (31.4% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at 12, accounting for 34.3% of all patches Background On May 28, Oracle released its Critical Security Patch Update (CSPU) for May 2026 . Beginning in May 2026, Oracle introduced CSPUs as a monthly release cycle that sits between the larger quarterly Critical Patch Updates (CPUs), addressing a focused set of high-severity issues on a faster cadence. This CSPU contains fixes for 35 unique CVEs in 35 security updates across 5 Oracle product families. Out of the 35 security updates published, 31.4% of patches were assigned a critical severity. High severity patches accounted for the bulk of security patches at 51.4%, followed by critical severity patches at 31.4%. This month's update includes 11 critical patches across 11 CVEs. Severity Issues Patched CVEs Critical 11 11 High 18 18 Medium 6 6 Low 0 0 Total 35 35 Analysis This month's update saw the Oracle E-Business Suite product family contain the highest number of patches at 12, accounting for 34.3% of the total patches, followed by Oracle REST Data Services at 11 patches, which accounted for 31.4% of the total patches. A full breakdown of the patches for this CSPU can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication. Oracle Product Family Number of Patches Remote Exploit without Auth Oracle E-Business Suite 12 3 Oracle REST Data Services 11 7 Oracle Communications 8 4 Oracle Database Server 3 3 Oracle Hospitality Applications 1 1 Solution Customers are advised to apply all relevant patches in this CSPU. Please refer to the May 2026 advisory for full details. Identifying affected systems A list of Tenable plugins to identify these vulnerabilities will appear here as they're released. This link uses a search filter to ensure that all matching plugin coverage will appear as it is released. Get more information Oracle Critical Security Patch Update Advisory - May 2026 Oracle May 2026 Critical Security Patch Update Risk Matrices Oracle Advisory to CVE Map Join Tenable's Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats. Learn more about Tenable One , the Exposure Management Platform for the modern attack surface.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The May 2026 Oracle CSPU contains 35 security updates fixing 35 unique CVEs, with 11 critical and 18 high severity issues. The patches cover five Oracle product families: Oracle E-Business Suite (12 patches), Oracle REST Data Services (11 patches), Oracle Communications (8 patches), Oracle Database Server (3 patches), and Oracle Hospitality Applications (1 patch). Multiple vulnerabilities allow remote exploitation without authentication, increasing the risk of compromise. This CSPU is part of Oracle's new monthly patch cycle introduced in May 2026 to address high-severity issues more rapidly.
Potential Impact
The vulnerabilities addressed include critical and high severity issues, some of which can be exploited remotely without authentication, potentially allowing attackers to compromise affected Oracle products. The Oracle E-Business Suite and Oracle REST Data Services are notably impacted with the highest number of patches. Exploitation could lead to unauthorized access, data breaches, or disruption of services depending on the specific vulnerabilities patched.
Mitigation Recommendations
Oracle has released official patches for all 35 vulnerabilities in this May 2026 CSPU. Customers should promptly apply all relevant patches to affected Oracle products as detailed in the official advisory. Since this is a traditional on-premises software update, remediation requires manual patch application by customers. Patch status is confirmed as official-fix. No indication of automatic or cloud service patching is provided.
Technical Details
- Article Source
- {"url":"https://www.tenable.com/blog/oracle-may-2026-critical-security-patch-update-addresses-35-cves","fetched":true,"fetchedAt":"2026-05-29T22:09:44.671Z","wordCount":2231}
Threat ID: 6a1a0ea9e29bf47b50184c1a
Added to database: 05/29/2026, 22:09:45 UTC
Last enriched: 05/29/2026, 22:09:51 UTC
Last updated: 07/31/2026, 12:57:28 UTC
Views: 229
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.