Oracle July 2026 Critical Patch Update Addresses 1235 CVEs
TenableArchived Jul 22, 2026✓ Full text saved
Oracle addresses 1235 CVEs in its third quarterly update of 2026 with 1449 patches, including 261 critical updates. Key Takeaways The third Critical Patch Update (CPU) for 2026 contains fixes for 1235 unique CVEs in 1449 security updates, the largest CPU release. 261 issues (18% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at 410, accounting for 28.3% of all patches Background On July 21, Oracle released its Critical Patc
Full text archived locally
✦ AI Summary· Claude Sonnet
Oracle July 2026 Critical Patch Update Addresses 1235 CVEs
By Research Special Operations
Subscribe
Oracle addresses 1235 CVEs in its third quarterly update of 2026 with 1449 patches, including 261 critical updates.
Key Takeaways
The third Critical Patch Update (CPU) for 2026 contains fixes for 1235 unique CVEs in 1449 security updates, the largest CPU release.
261 issues (18% of all patches) were assigned a critical severity rating
Oracle E-Business Suite received the highest number of patches at 410, accounting for 28.3% of all patches
Background
On July 21, Oracle released its Critical Patch Update (CPU) for July 2026, the third quarterly update of the year. This CPU contains fixes for 1235 unique CVEs in 1449 security updates across 32 Oracle product families. Out of the 1449 security updates published this quarter, 18% of patches were assigned a critical severity. High severity patches accounted for the bulk of security patches at 52.7%, followed by medium severity patches at 24.7%.
This quarter's update includes 261 critical patches across 228 CVEs.
Severity
Issues Patched
CVEs
Critical
261
228
High
763
613
Medium
358
332
Low
67
62
Total
1449
1235
Analysis
This quarter, the Oracle E-Business Suite product family contained the highest number of patches at 410, accounting for 28.3% of the total patches, followed by Oracle Fusion Middleware at 355 patches, which accounted for 24.5% of the total patches.
A full breakdown of the patches for this quarter can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication.
Oracle Product Family
Number of Patches
Remote Exploit without Auth
Oracle E-Business Suite
410
45
Oracle Fusion Middleware
355
219
Oracle Communications
168
122
Oracle PeopleSoft
84
45
Oracle MySQL
54
9
Oracle Siebel CRM
45
32
Oracle Commerce
39
26
Oracle Supply Chain
39
16
Oracle Financial Services Applications
31
26
Oracle GoldenGate
27
9
Oracle Enterprise Manager
27
13
Oracle Retail Applications
22
20
Oracle JD Edwards
20
4
Oracle Java SE
19
17
Oracle Virtualization
16
0
Oracle Database Server
15
6
Oracle TimesTen In-Memory Database
14
4
Oracle Utilities Applications
14
10
Oracle Construction and Engineering
7
7
Oracle Analytics
7
5
Oracle Systems
6
0
Oracle SQL Developer
5
5
Oracle Autonomous Health Framework
4
3
Oracle Application Testing Suite
4
4
Oracle Food and Beverage Applications
4
4
Oracle HealthCare Applications
4
4
Oracle APEX
3
2
Oracle Hospitality Applications
2
2
Oracle Essbase
1
1
Oracle Global Lifecycle Management
1
1
Oracle NoSQL Database
1
1
Oracle Spatial Studio
1
1
Solution
Customers are advised to apply all relevant patches in this quarter's CPU. Please refer to the July 2026 advisory for full details.
Identifying affected systems
A list of Tenable plugins to identify these vulnerabilities will appear here as they're released. This link uses a search filter to ensure that all matching plugin coverage will appear as it is released.
Join Tenable's Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.
Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.
Author
Learn more
Research Special Operations
The Research Special Operations (RSO) team serves as Tenable’s Forward Logistics Element in the threat landscape, providing customers with the analyses and contextualized exposure intelligence required to manage risks to critical business assets. With over 150 years of collective expertise, this han...
Read more
Oracle Critical Patch Update Advisory - July 2026
Oracle July 2026 Critical Patch Update Risk Matrices
Oracle Advisory to CVE Map
Related articles
AI SECURITY
JUL 21 2026
Your AI agent’s config is now the payload: How attackers are targeting the…
By Tom Abai
CYBER EXPOSURE ALERTS
JUL 20 2026
wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about…
By Satnam Narang
CYBER EXPOSURE ALERTS
JUL 16 2026
CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions…
By Research Special Operations
Exposure Management
Vulnerability Management
Tenable Lumin
Tenable Nessus
Tenable Nessus Network Monitor
Tenable One
Tenable Patch Management
Tenable Security Center
Tenable Security Center Plus
Tenable Vulnerability Management