Oracle's June 2026 CPU: 245 Patches Across Communications, EBS, and Enterprise Manager

Oracle's second monthly Critical Patch Update ships a heavy fix load. If you're running EBS or Enterprise Manager on EC2, Exadata Cloud Service, or on-prem, your change window just got scheduled for you.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 2 min read
Oracle's June 2026 CPU: 245 Patches Across Communications, EBS, and Enterprise Manager
Share

Key points

  • Oracle released its June 2026 Critical Patch Update, covering 245 fixes across Communications, EBS, Enterprise Manager and other products.
  • The monthly cadence, introduced in 2025, continues to outpace most enterprise change management workflows.
  • Enterprise Manager is a management plane: leave it unpatched and a single compromise can reach every Oracle instance it monitors.
  • Communications products are in scope, which matters for telcos and financial services firms running Oracle billing and provisioning stacks.
  • Oracle's public summary had not broken out per-CVE CVSS scores at the time of writing.

How bad is the fix load?

245 patches is a significant number for teams still adjusting to monthly Oracle updates. The company moved to a monthly cadence in 2025, and most enterprises haven't matched their patching rhythms to it. Quarterly was already a stretch. Monthly is genuinely hard.

When we covered Oracle's first monthly drop on 1 June, the list was 35 fixes, including a CVSS 10 hole in REST Data Services. This update is seven times that volume.

Should you worry about Enterprise Manager first?

Yes. Platform engineers running Oracle EBS on EC2 or Exadata Cloud Service see the advisory, triage severity, then hit the change management queue. By the time CAB approves the window, you're three weeks out and the CVEs are public.

Enterprise Manager is the uncomfortable one. Compromise the management plane and you don't just own one Oracle instance: you potentially have lateral reach across everything it monitors. That blast radius makes a postmortem very uncomfortable to write.

What about Communications products?

Communications products in scope is the detail worth flagging for telcos and financial services firms. Oracle's billing and provisioning stack runs inside a lot of infrastructure that's hard to patch quickly because of upstream dependency chains and vendor support contracts. The window between advisory and applied patch is where exposure lives.

Common questions

Is the full severity breakdown available?

Not yet. Oracle had not published per-CVE CVSS scores across all 245 fixes in the public summary at the time of writing. Check the official Oracle advisory for affected product versions and current patch availability.

Does this affect on-prem deployments too?

Yes. EBS and Enterprise Manager deployments on-prem are in scope alongside cloud-hosted instances on EC2 and Exadata Cloud Service.

What's the one thing to act on right now?

If you own Enterprise Manager, treat it as the priority. Everything downstream of it is only as secure as the management plane watching it. If something goes wrong and you haven't patched, the post-mortem writes itself: the fix was available.

© 2026 Threat Vectr