Full Report
Oracle addresses 1235 CVEs in its third quarterly update of 2026 with 1449 patches, including 261 critical updates.Key TakeawaysThe third Critical Patch Update (CPU) for 2026 contains fixes for 1235 unique CVEs in 1449 security updates, the largest CPU release.261 issues (18% of all patches) were assigned a critical severity ratingOracle E-Business Suite received the highest number of patches at 410, accounting for 28.3% of all patchesBackgroundOn July 21, Oracle released its Critical Patch Update (CPU) for July 2026, the third quarterly update of the year. This CPU contains fixes for 1235 unique CVEs in 1449 security updates across 32 Oracle product families. Out of the 1449 security updates published this quarter, 18% of patches were assigned a critical severity. High severity patches accounted for the bulk of security patches at 52.7%, followed by medium severity patches at 24.7%.This quarter's update includes 261 critical patches across 228 CVEs.SeverityIssues PatchedCVEsCritical261228High763613Medium358332Low6762Total14491235AnalysisThis quarter, the Oracle E-Business Suite product family contained the highest number of patches at 410, accounting for 28.3% of the total patches, followed by Oracle Fusion Middleware at 355 patches, which accounted for 24.5% of the total patches.A full breakdown of the patches for this quarter can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication.Oracle Product FamilyNumber of PatchesRemote Exploit without AuthOracle E-Business Suite41045Oracle Fusion Middleware355219Oracle Communications168122Oracle PeopleSoft8445Oracle MySQL549Oracle Siebel CRM4532Oracle Commerce3926Oracle Supply Chain3916Oracle Financial Services Applications3126Oracle GoldenGate279Oracle Enterprise Manager2713Oracle Retail Applications2220Oracle JD Edwards204Oracle Java SE1917Oracle Virtualization160Oracle Database Server156Oracle TimesTen In-Memory Database144Oracle Utilities Applications1410Oracle Construction and Engineering77Oracle Analytics75Oracle Systems60Oracle SQL Developer55Oracle Autonomous Health Framework43Oracle Application Testing Suite44Oracle Food and Beverage Applications44Oracle HealthCare Applications44Oracle APEX32Oracle Hospitality Applications22Oracle Essbase11Oracle Global Lifecycle Management11Oracle NoSQL Database11Oracle Spatial Studio11SolutionCustomers are advised to apply all relevant patches in this quarter's CPU. Please refer to the July 2026 advisory for full details.Identifying affected systemsA list of Tenable plugins to identify these vulnerabilities will appear here as they're released. This link uses a search filter to ensure that all matching plugin coverage will appear as it is released.Get more informationOracle Critical Patch Update Advisory - July 2026Oracle July 2026 Critical Patch Update Risk MatricesOracle Advisory to CVE MapJoin Tenable's Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.
Analysis Summary
# Vulnerability: Oracle July 2026 Critical Patch Update (CPU)
## CVE Details
- **CVE ID:** 1,235 unique CVEs addressed (Individual IDs documented in vendor advisory).
- **CVSS Score:** Up to 10.0 (Critical).
- **CWE:** Multiple (Varies by product family; typically includes Injection, Broken Access Control, and Insecure Deserialization).
## Affected Systems
- **Products:** 32 Oracle product families including:
- Oracle E-Business Suite (410 patches)
- Oracle Fusion Middleware (355 patches)
- Oracle Communications (168 patches)
- Oracle PeopleSoft (84 patches)
- Oracle MySQL (54 patches)
- Oracle Java SE (19 patches)
- Oracle Database Server (15 patches)
- **Versions:** Multiple supported versions across the product lines list above.
- **Configurations:** Systems exposed to the network are at higher risk; 663 vulnerabilities (approx. 46% of patches) are exploitable remotely without authentication.
## Vulnerability Description
This is a cumulative update addressing 1,449 security flaws across the Oracle ecosystem. The flaws range from remote code execution (RCE) and cross-site scripting (XSS) to denial-of-service (DoS) and unauthorized data access. Notably, Oracle Fusion Middleware and Communications have the highest density of remote, unauthenticated exploitable vulnerabilities.
## Exploitation
- **Status:** Vulnerabilities are patched; however, no specific mention of "in the wild" exploitation in the summary (refer to individual CVEs for live status).
- **Complexity:** Ranges from Low to High.
- **Attack Vector:** Primarily **Network** (663 vulnerabilities are remotely exploitable without credentials).
## Impact
- **Confidentiality:** High (261 patches address Critical severity issues).
- **Integrity:** High (Widespread impact across 32 product suites).
- **Availability:** High (Common impact for Database and Middleware components).
## Remediation
### Patches
Oracle has released 1,449 patches. Administrators should apply the July 2026 CPU immediately, prioritizing the following:
- **Oracle E-Business Suite:** Versions impacted by 410 new fixes.
- **Oracle Fusion Middleware:** Priority for the 219 vulnerabilities exploitable without authentication.
- **Oracle Communications:** Priority for the 122 vulnerabilities exploitable without authentication.
### Workarounds
Oracle generally does not provide workarounds for CPU vulnerabilities. Restricting network access to affected services to only trusted hosts is recommended until patches are applied.
## Detection
- **Indicators of Compromise:** Monitor for unusual administrative login attempts and unauthorized network traffic to Oracle listeners/web ports.
- **Detection Methods:** Utilize Tenable plugins or other vulnerability scanners.
- **Search Filter:** Use keywords "(July 2026 CPU)" in scanning tools to locate relevant plugins as they are released.
## References
- Oracle July 2026 Advisory: hxxps[:]//www[.]oracle[.]com/security-alerts/cpujul2026[.]html
- Oracle July 2026 Risk Matrices: hxxps[:]//www[.]oracle[.]com/security-alerts/cpujul2026verbose[.]html
- Tenable Blog: hxxps[:]//www[.]tenable[.]com/blog/oracle-july-2026-critical-patch-update-addresses-1235-cves