Oracle July 2026 CPU Addresses Record 1235 CVEs, With 261 Critical Patches
Oracle's July 2026 Critical Patch Update (CPU) is its largest quarterly release, fixing 1235 unique CVEs across 32 product families with 1449 patches, including 261 rated critical.

Oracle has released its third Critical Patch Update (CPU) for 2026, a substantial release that addresses a record-breaking 1235 unique Common Vulnerabilities and Exposures (CVEs) across 32 of its product families. This update comprises 1449 individual security patches, marking it as the largest CPU release to date. A significant portion of these fixes, 261 patches or approximately 18% of the total, are classified as critical severity, indicating a high potential for exploitation.
The vast majority of the patches, 52.7%, are rated as high severity, followed by 24.7% rated as medium severity. This distribution underscores the broad range of security risks Oracle is working to mitigate for its extensive customer base. The company's commitment to addressing vulnerabilities through regular patch cycles remains a critical component of its security strategy.
Among the affected product families, Oracle E-Business Suite stands out, receiving the highest number of patches with 410. This accounts for a considerable 28.3% of all patches released in this CPU cycle. Following closely is Oracle Fusion Middleware, which received 355 patches, representing 24.5% of the total. These two product lines alone account for over half of the security updates issued this quarter, highlighting their importance and the complexity of their security posture.
Other product families also received significant attention. Oracle Communications saw 168 patches, Oracle PeopleSoft received 84, and Oracle MySQL was addressed with 54 patches. A detailed breakdown reveals that many of these vulnerabilities can be exploited remotely without requiring authentication, increasing the urgency for organizations to apply these patches promptly. For instance, Oracle E-Business Suite has 45 vulnerabilities that can be exploited over a network without authentication, and Oracle Fusion Middleware has 219 such vulnerabilities.
This extensive update cycle reflects the ongoing challenges in securing complex enterprise software environments. The sheer volume of CVEs addressed suggests a continuous effort by Oracle to identify and remediate security weaknesses across its diverse product portfolio. The company's proactive approach through these quarterly CPUs is essential for customers to maintain a strong security posture against evolving threats.
Customers are strongly advised to review the July 2026 advisory and apply all relevant patches as soon as possible. The company provides detailed risk matrices and advisory-to-CVE maps to assist organizations in prioritizing their patching efforts. Proactive vulnerability management, including timely application of these critical updates, is paramount to preventing potential security breaches and ensuring the integrity of business operations.
Organizations relying on Oracle products should consult the official Oracle Critical Patch Update Advisory for July 2026 for comprehensive details on each vulnerability and its associated product. Tenable has also indicated that plugins to identify these vulnerabilities will be released, aiding customers in their detection and remediation efforts. Staying informed and acting swiftly on these updates is crucial for mitigating the risks associated with such a large volume of critical and high-severity vulnerabilities.
The scale of this CPU release emphasizes the dynamic nature of cybersecurity threats and the continuous need for vigilance. By addressing 1235 CVEs, Oracle is providing its users with the necessary tools to defend against potential attacks, but the responsibility ultimately lies with the customers to implement these security measures effectively.