Oracle Pushes 943 Security Fixes in August 2026 Patch Update

Oracle's latest monthly security release covers more than 1,000 flaws across two dozen products, including nearly 90 critical bugs that score almost perfectly on the industry's severity scale.

ThreatVectr Newsdesk· 3 min read
Overhead photoreal editorial shot of a server rack room bathed in cold blue-white fluorescent light, dense cables running between black rack units, a single amb
Share

Key points

  • Oracle released 943 security patches on Tuesday as part of its August 2026 Critical Security Patch Update, covering more than 1,000 individual software flaws.
  • Over 460 of those flaws can be exploited by an outsider without needing a username or password.
  • Nearly 90 vulnerabilities carry a CVSS score (a standardised severity rating from 0 to 10) of 9.8 or higher, placing them at the extreme end of the danger scale.
  • Oracle Fusion Middleware and Hyperion each received 262 patches, the highest counts in this release.
  • Oracle says it is using large language models, a type of artificial intelligence, to find and fix vulnerabilities faster.

Oracle, the company behind a wide range of business software used by hospitals, retailers, banks, and governments worldwide, dropped a large batch of security fixes on Tuesday. The August 2026 Critical Security Patch Update, or CSPU, contains 943 individual patches that together close more than 1,000 distinct software flaws.

How serious are these flaws?

Very. More than 150 of the bugs are classed as critical severity, meaning attackers could use them to cause serious harm. Nearly 90 of those score 9.8 or above on the CVSS scale, the industry's standard 0-to-10 rating for how dangerous a flaw is.

The scariest number is 460-plus. That is how many of the vulnerabilities can be exploited remotely and without authentication, which means a criminal sitting anywhere on the internet could potentially attack a system without ever needing a stolen password. The failure mode here is straightforward: unpatched server, internet-facing, game over.

Which products are affected?

The two heaviest hitters are Oracle Fusion Middleware, a platform large organisations use to connect different software systems together, and Oracle Hyperion, a financial planning tool. Each received 262 patches. Fusion Middleware alone carries 182 flaws that outside attackers can hit without a login.

The full list is long. Oracle also patched E-Business Suite (120 fixes), Commerce (66), Siebel CRM (50), and Supply Chain (46). Java SE, MySQL, VM VirtualBox, and PeopleSoft all got fixes too.

Product Patches issued Critical flaws
Fusion Middleware 262 80
Hyperion 262 27
E-Business Suite 120 Not disclosed
Commerce 66 Not disclosed
Siebel CRM 50 Not disclosed
Supply Chain 46 Not disclosed

For context, the July 2026 patch update included 1,449 fixes across more than 1,400 CVEs (CVE stands for Common Vulnerabilities and Exposures, the standard catalogue used to track individual software flaws). August's release is large, but not the biggest Oracle has shipped this year.

Why so many patches all at once?

Oracle said earlier this year that it is using advanced AI models to speed up the process of finding and patching vulnerabilities. More automated discovery means more fixes reaching customers faster. In practice, it also means the patch lists are getting longer, which creates its own operational headache for the teams that have to apply them.

One thing the post-mortem will say after any future Oracle-related breach: the patch was available. Oracle itself warns that criminals have repeatedly tried to exploit flaws that the company had already fixed. Organisations running Oracle software that delay applying updates are handing attackers a roadmap.

If your employer uses Oracle software at work, ask your IT team whether Tuesday's patches are on the schedule. Delays measured in weeks are measured in risk.

© 2026 Threat Vectr