Oracle Launches Monthly Patch Cycle With 35-Flaw Drop, Four CVEs Under Active PoC Threat
A CVSS 10 hole in REST Data Services leads the list. Four older bugs with public exploit code deserve faster attention than their scores suggest.

Oracle shipped the inaugural release of its new Critical Security Patch Update cycle last Thursday — 35 vulnerabilities fixed, 11 rated critical, 18 rated high. The monthly CSPU format is Oracle's answer to the same problem that pushed Microsoft to Patch Tuesday years ago: quarterly schedules leave too much room between discovery and fix.
The headliner on paper is CVE-2026-46840, a CVSS 10 in the backend-as-a-service component of Oracle REST Data Services versions 24.2.0 through 26.1.0. REST Data Services is the API gateway companies use to expose their corporate databases externally. An unauthenticated attacker can reach it over HTTPS and take the gateway over entirely. No credentials. No foothold required. That profile puts it at the top of any attacker's interest list.
Two companion flaws — CVE-2026-46775 and CVE-2026-46839 — hit REST Data Services' core components and score CVSS 9.9. Network credentials are the only thing keeping them off a perfect score.
Despite those numbers, patching teams should probably start elsewhere. Four CVEs carry confirmed proof-of-concept exploit code: CVE-2025-15467, CVE-2025-58050, and CVE-2026-25646 in Oracle Communications Unified Assurance, plus CVE-2026-2332 in REST Data Services again. All four trace back to open-source components embedded in Oracle products — a supply-chain lag problem the industry has yet to solve cleanly. CVE-2025-58050 first surfaced publicly last August. Seventeen months from disclosure to vendor patch.
Other notable fixes cover Oracle E-Business Suite (CVE-2026-46822), the Oracle Universal Work Queue portal (CVE-2026-46824), and Oracle Payments (CVE-2026-46817).
Oracle has said it participates in AI-assisted vulnerability hunting programs — including OpenAI's Trusted Access for Cyber and Anthropic's Claude Mythos. None of this month's discoveries were attributed to either system.
Future CSPUs land on the third Tuesday of each month. The next four are scheduled for June 16, July 21, August 18, and September 15. The quarterly Critical Patch Update schedule continues alongside it. Oracle cloud customers receive patches automatically; on-premises operators need to move themselves.



