CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4673

As cited

Copy frozen at (site build).

vulnerabilities

Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs

Oracle released its August 2026 Critical Security Patch Update on August 18, addressing 925 CVEs across 943 patches in 23 product families, with 154 patches rated critical severity. This represents a significant increase from the June 2026 CSPU and comprises approximately 65 percent of the quarterly July CPU volume, blurring the distinction between monthly targeted and quarterly comprehensive releases. Oracle Fusion Middleware and Hyperion accounted for over half of all patches, with 182 and 107 issues respectively exploitable remotely without authentication.

Why it matters: Organizations running Oracle Fusion Middleware, Hyperion, E-Business Suite, or other affected products must prioritize patching 154 critical vulnerabilities, particularly the 289 remote network exploits without authentication in Middleware and Hyperion, to prevent immediate compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs

Oracle released its August 2026 Critical Security Patch Update on August 18, addressing 925 CVEs across 943 patches in 23 product families, with 154 patches rated critical severity. This represents a significant increase from the June 2026 CSPU and comprises approximately 65 percent of the quarterly July CPU volume, blurring the distinction between monthly targeted and quarterly comprehensive releases. Oracle Fusion Middleware and Hyperion accounted for over half of all patches, with 182 and 107 issues respectively exploitable remotely without authentication.

Why it matters: Organizations running Oracle Fusion Middleware, Hyperion, E-Business Suite, or other affected products must prioritize patching 154 critical vulnerabilities, particularly the 289 remote network exploits without authentication in Middleware and Hyperion, to prevent immediate compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs

Oracle released its August 2026 Critical Security Patch Update on August 18, addressing 925 CVEs across 943 patches in 23 product families, with 154 patches rated critical severity. This represents a significant increase from the June 2026 CSPU and comprises approximately 65 percent of the quarterly July CPU volume, blurring the distinction between monthly targeted and quarterly comprehensive releases. Oracle Fusion Middleware and Hyperion accounted for over half of all patches, with 182 and 107 issues respectively exploitable remotely without authentication.

Why it matters: Organizations running Oracle Fusion Middleware, Hyperion, E-Business Suite, or other affected products must prioritize patching 154 critical vulnerabilities, particularly the 289 remote network exploits without authentication in Middleware and Hyperion, to prevent immediate compromise.

VendorsAdobeOracle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary