Skip to content

Oracle Critical Patch Update Fixes 1235 CVEs Across 32 Product Families

Oracle's July 2026 Critical Patch Update patches 1235 CVEs in 1449 security fixes across 32 product families, including 228 rated critical severity.

Oracle Cloud Infrastructure illustration showing a global distributed cloud network
Credit: Oracle

Oracle released its July 2026 Critical Patch Update on July 21, the company's third quarterly security cycle of the year.

The release covers 1235 CVEs in 1449 security patches across 32 product families, per Oracle's advisory. Of those, 261 patches carry critical severity, covering 228 distinct CVEs and representing 18% of the total patch count. High-severity patches account for 763 updates across 613 CVEs, followed by medium at 358 patches (332 CVEs) and low at 67 patches (62 CVEs). Oracle notes that attackers have repeatedly exploited vulnerabilities in systems where available patches had not been applied, and strongly recommends that customers on actively supported product versions apply fixes without delay.

Oracle E-Business Suite received the highest patch count of any product family at 410 updates, representing 28.3% of the release and including 45 vulnerabilities exploitable over a network without authentication. Oracle Fusion Middleware follows with 355 patches and the update's sharpest unauthenticated exposure: 219 of its vulnerabilities are remotely exploitable without credentials, making Fusion Middleware instances a top remediation priority for organizations running internet-accessible Oracle middleware. Oracle Communications rounds out the top three at 168 patches, 122 of which carry no authentication requirement for remote network exploitation.

Oracle PeopleSoft received 84 patches (45 remotely exploitable without authentication), Oracle MySQL 54 (9 remote, no auth required), and Oracle Siebel CRM 45 (32 remote, no auth). The Oracle Database Server received 15 patches, 6 exploitable remotely without credentials; Oracle Java SE got 19 patches with 17 involving network attack vectors. Across the full release, more than 600 of the 1449 patches address vulnerabilities that can be exploited over a network without an authenticated session.

For enterprise security teams, Oracle Fusion Middleware's combination of patch volume and unauthenticated remote attack surface makes it the clearest starting point for remediation sequencing in the July update. Customers running Oracle products outside active support windows will not receive these patches and may be permanently exposed to flaws already documented in Oracle's July 2026 Critical Patch Update Advisory.

Share this story

Daniel Brandt

Daniel Brandt covers threats, malware, and vulnerability disclosure for techshooked, from active exploit campaigns to the patch cycles that follow. His standard is operational: name the affected versions, separate a proof of concept from in-the-wild exploitation, and tell readers which fix to apply first.