CYBERSECURITYTRACKER
TRACKING4,295 stories803 vuln stories
Permanent story citation

Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs

The story is preserved as cited. Later corrections remain visibly typed and adjacent to the original snapshot.

← newsStory 4673

As cited

Citation snapshot as of .

vulnerabilities

Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs

Oracle released its August 2026 Critical Security Patch Update on August 18, addressing 925 CVEs across 943 patches in 23 product families, with 154 patches rated critical severity. This represents a significant increase from the June 2026 CSPU and comprises approximately 65 percent of the quarterly July CPU volume, blurring the distinction between monthly targeted and quarterly comprehensive releases. Oracle Fusion Middleware and Hyperion accounted for over half of all patches, with 182 and 107 issues respectively exploitable remotely without authentication.

Why it matters: Organizations running Oracle Fusion Middleware, Hyperion, E-Business Suite, or other affected products must prioritize patching 154 critical vulnerabilities, particularly the 289 remote network exploits without authentication in Middleware and Hyperion, to prevent immediate compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution