Oracle Pushes 943 Security Fixes in August 2026 Patch Update
Oracle's August 2026 security release closes more than 1,000 flaws across two dozen products, with nearly 90 critical bugs scoring 9.8 or higher on the industry's 0-to-10 severity scale.

Key points
- Oracle released 943 security patches on Tuesday as part of its August 2026 Critical Security Patch Update, covering more than 1,000 individual software flaws.
- Over 460 of those flaws can be exploited by an outsider without needing a username or password.
- Nearly 90 vulnerabilities carry a CVSS score (a standardised severity rating from 0 to 10) of 9.8 or higher.
- Oracle Fusion Middleware and Hyperion each received 262 patches, the highest counts in this release.
- Oracle says it's using large language models to find and fix vulnerabilities faster.
Oracle, whose business software runs in hospitals, retailers, banks and governments worldwide, dropped a large batch of security fixes on Tuesday. The August 2026 Critical Security Patch Update, or CSPU, contains 943 individual patches closing more than 1,000 distinct flaws.
How serious are these flaws?
Very. More than 150 bugs are classed as critical severity, and nearly 90 of them score 9.8 or above on the CVSS scale, the industry's standard 0-to-10 danger rating.
The number that matters most is 460-plus: vulnerabilities exploitable remotely without authentication, meaning an attacker anywhere on the internet can potentially hit an unpatched server without a stolen password. Unpatched, internet-facing, done.
Which products are affected?
Fusion Middleware, a platform large organisations use to connect disparate software systems, and Hyperion, a financial planning tool, each received 262 patches. Fusion Middleware carries 182 remotely exploitable flaws requiring no login; Hyperion carries 107. Oracle also patched E-Business Suite (120 fixes), Commerce (66), Siebel CRM (50) and Supply Chain (46). VM VirtualBox, Analytics, MySQL, PeopleSoft and roughly a dozen other products got fixes too.
| Product | Patches issued | Critical flaws |
|---|---|---|
| Fusion Middleware | 262 | 80 |
| Hyperion | 262 | 27 |
| E-Business Suite | 120 | Not disclosed |
| Commerce | 66 | Not disclosed |
| Siebel CRM | 50 | Not disclosed |
| Supply Chain | 46 | Not disclosed |
August's release is large but not Oracle's biggest this year. July's Critical Patch Update included 1,449 fixes addressing over 1,400 CVEs (CVE stands for Common Vulnerabilities and Exposures, the standard catalogue for tracking individual software flaws).
Why so many patches all at once?
Oracle said earlier this year it's using advanced large language models (a type of AI) to speed up vulnerability discovery. More automated discovery means more fixes shipped faster. It also means patch lists that are growing longer, which is its own operational burden for the teams applying them. August 2026 has been a busy patch month generally: our coverage of the ICS Patch Tuesday on 12 August found a Siemens flaw at maximum severity that similarly required no credentials to exploit.
Should you worry?
If your organisation runs Oracle software, yes. Oracle itself warns that attackers have repeatedly tried to exploit flaws for which patches were already available. The company's advisory is direct: apply these updates as soon as possible.
The post-mortem after any future Oracle-related breach will say the patch existed. Delays measured in weeks translate directly into exposure. Ask your IT team whether Tuesday's fixes are scheduled.



