# Oracle software security vulnerabilities and patching

> Live situation record from CLSTR: https://clstr.news/situations/oracle-software-security-vulnerabilities-and-patching
> Updated: 2026-08-25T00:00:00.000Z. Sources: 7. Developments: 2.

Oracle has implemented a monthly patching cadence to address a rise in AI-driven vulnerability identification. In August 2026, the company released 943 security patches to address 925 unique Common Vulnerabilities and Exposures (CVEs), including 154 critical updates. Oracle noted that some customers have been compromised through known vulnerabilities that remained unpatched.

Concurrently, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical vulnerability in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in to its Known Exploited Vulnerabilities (KEV) Catalog. Identified as CVE-2026-21962, the flaw carries a maximum CVSS score of 10.0 and involves improper access control that allows unauthenticated attackers to bypass authorization. Although Oracle released patches for this specific flaw in January 2026, reports indicate it is being actively exploited in the wild, prompting a mandate for Federal Civilian Executive Branch agencies to address it.

## Timeline

### 2026-08-25: Oracle HTTP Server vulnerability added to CISA's KEV Catalog

CISA has added a critical Oracle HTTP Server and WebLogic vulnerability (CVE-2026-21962) to its KEV Catalog following evidence of active exploitation by unauthenticated attackers.

5 sources. https://clstr.news/cluster/oracle-http-server-vulnerability-added-to-cisas-kev-catalog

### 2026-08-19: Oracle releases 943 security patches to address critical vulnerabilities

Oracle released 943 security patches in August 2026 to fix 925 unique vulnerabilities, including 154 critical issues across 23 product families like Fusion Middleware and PeopleSoft.

3 sources. https://clstr.news/cluster/oracle-releases-943-security-patches-to-address-critical-vulnerabilities

---
Cite as: Oracle software security vulnerabilities and patching. CLSTR, https://clstr.news/situations/oracle-software-security-vulnerabilities-and-patching
