Oracle's Largest Patch Update Fixes Hundreds of Vulnerabilities
Oracle releases its biggest Critical Patch Update yet, addressing severe vulnerabilities in multiple products.

Key points
- Oracle released 1,449 security patches in July 2026.
- 355 vulnerabilities in Fusion Middleware, 219 remotely exploitable.
- CVE-2026-61211 in Oracle Database Server scored 9.9 on CVSS.
- New monthly patch cadence introduced alongside quarterly updates.
Oracle's July 2026 Critical Patch Update marks its largest release ever, addressing 1,449 security issues across 32 product families. This includes popular software like Oracle Database, E-Business Suite, and Fusion Middleware. The update, first reported by CSO Online, is a crucial step for organizations using these products to secure their systems.
Fusion Middleware experienced the highest number of fixes, with 355 vulnerabilities addressed. Out of these, 219 can be exploited over a network without needing a password, making them particularly dangerous. Ten of these vulnerabilities got a perfect 10.0 score on the Common Vulnerability Scoring System (CVSS), meaning they are critical and easily exploitable. They affect key components like Oracle Data Integrator and Oracle HTTP Server, potentially allowing hackers to break into these systems.
The flagship Oracle Database Server also received attention, with two major vulnerabilities patched. The most severe, CVE-2026-61211, is a flaw in the database management system's cloud package that scored 9.9 on the CVSS. It allows attackers with minimal access rights to take over the database if it's configured in a specific way. This vulnerability affects versions 19.3 through 19.31 and 23.4.0 through 23.26.2 of the Database Server. Another flaw, CVE-2026-47040, is remotely exploitable without credentials, impacting the Oracle Net Services.
Should customers be worried?
Yes, especially if they use Oracle's affected products. The vulnerabilities in Fusion Middleware and Database Server are significant because they can be exploited by hackers without needing a password, making systems more vulnerable to attacks. Organizations should prioritize patching these systems promptly to protect sensitive data.
Oracle's chief security analyst, Sanchit Vir Gogia, advised that the urgency of patching depends on each system's configuration. Businesses where the vulnerable components are widely accessible should act within seventy-two hours.
This update introduces a new monthly cycle for security patches, on top of the quarterly cycle. Despite this, many organizations have been slow to adopt the new monthly rhythm due to the complexity of aligning different teams and systems for patching. Vibhum Dubey, a cybersecurity researcher, noted that patching is often an operational challenge rather than a technical one.
Experts like Niyati Daftary from Gartner emphasize that patching is about reducing risk efficiently rather than fixing every vulnerability. Organizations should focus on the most vulnerable parts of their systems, especially those exposed to the internet.
Oracle's next update is scheduled for October 20, 2026, with smaller updates in August and September. Companies should plan their patching strategies accordingly to keep their systems secure.



