< Back to all clusters
[TECHNOLOGY] · 3 sources

started · updated

Oracle releases 943 security patches to address critical vulnerabilities

Oracle has released its August 2026 Critical Security Patch Update (CSPU), providing 943 patches to address 925 unique Common Vulnerabilities and Exposures (CVEs). This release includes 154 critical updates, with three vulnerabilities receiving a maximum CVSS impact score of 10.0.

The update covers 23 product families, a significant increase from previous monthly cycles. Oracle Fusion Middleware received the highest volume of patches, accounting for 262 updates. Other affected products include Oracle Internet Directory, Oracle Identity Manager, Oracle Managed File Transfer, Oracle WebLogic Server, and Oracle PeopleSoft.

Oracle transitioned to a monthly patching cadence in May 2026 to better respond to the rise of AI-driven tools used to identify vulnerabilities. The company has noted that some customers have been compromised via known vulnerabilities for which patches were previously available but not installed.

Entities

Oracle