Oracle Patches 1,434 Flaws in One Go. AI Probably Found Most of Them.

Oracle's July 2026 quarterly security update is the largest in the company's history, covering hundreds of products used by hospitals, banks, retailers, and governments worldwide.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial image, full-frame edge-to-edge 16:9 composition
Share

Key points

  • Oracle released 1,449 security patches on its July 2026 quarterly update date, covering 1,434 unique vulnerabilities across 334 products.
  • Roughly 600 of the patched flaws could be exploited remotely by anyone with an internet connection, no password required.
  • External security researchers were credited for only a few dozen discoveries, suggesting Oracle's own AI tools found the vast majority.
  • Oracle has confirmed it uses Anthropic's Claude Mythos and OpenAI's most capable models to hunt for software weaknesses.
  • Criminals have actively attacked unpatched Oracle systems in recent months, including a zero-day hit on PeopleSoft and a flaw in Oracle E-Business Suite.

Oracle, the American technology company whose software runs payroll, hospital records, retail inventory, and financial systems for thousands of organisations globally, has issued its largest-ever quarterly security update. The July 2026 Critical Patch Update, which is Oracle's name for its scheduled bundle of security fixes released four times a year, contains 1,449 patches fixing 1,434 distinct CVEs. A CVE, short for Common Vulnerabilities and Exposures, is the standard reference number given to each confirmed software flaw.

The sheer volume is striking. For comparison, Oracle's previous quarterly bundle delivered 245 patches, first reported by SecurityWeek at the time.

Products covered include Oracle Database Server, Java SE (the programming platform installed on billions of devices), MySQL (a widely used database system), E-Business Suite, Fusion Middleware, PeopleSoft, and dozens more. E-Business Suite alone accounts for 410 of the fixes. Fusion Middleware follows with 355, and Communications products account for 168.

How did Oracle find so many bugs at once?

Oracle found most of them itself, almost certainly with the help of artificial intelligence. Outside researchers received credit for only a few dozen of the 1,434 CVEs. Earlier this year Oracle disclosed that it has integrated top-tier AI models, including Anthropic's Claude Mythos and OpenAI's most powerful systems, directly into its process for scanning its own code for weaknesses. The company says it applies this AI-assisted hunting across its own software, Oracle Health products, and the open-source components it ships.

That is notable because finding software vulnerabilities has historically been slow, expensive, manual work. AI can read and analyse code far faster than a human researcher.

The urgency of patching is real. Roughly 600 of the newly fixed flaws are rated as remotely exploitable without authentication, meaning a criminal could attack a vulnerable server from anywhere on the internet without needing a username or password first. Hundreds carry a critical severity rating.

Criminals have not been waiting. Oracle PeopleSoft, the software many large employers use for HR and payroll, was hit by a zero-day (a flaw that was unknown and therefore unpatched at the time criminals started using it). A separate flaw in Oracle E-Business Suite was also recently exploited in attacks, with cosmetics giant Estée Lauder among the affected organisations.

If your employer, doctor, bank, or utility provider runs Oracle software, the patch is available now. The practical ask for ordinary people is simple: if you receive any unusual emails claiming your account details have changed, or if online portals you use behave oddly in coming weeks, report it rather than ignore it.

© 2026 Threat Vectr