Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

Oracle Critical Patch Update for July 2026 ships 1,448 patches, 410 for E-Business Suite

The quarterly release fixed flaws across Database, E-Business Suite, PeopleSoft and JD Edwards, with ten Fusion Middleware entries rated 10.0 for severity.

By · Editor

· Archive story, added · 3 min read · ✓ Fact-checked

The 60-second brief

  • 1Oracle released 1,448 new security patches on July 21, 2026, including 410 for E-Business Suite.
  • 2Ten Fusion Middleware entries carried the maximum 10.0 severity score and were rated exploitable without a login.
  • 3Oracle now also ships smaller Critical Security Patch Updates in the months between quarterly releases.

The news

On July 21, 2026, Oracle (ORCL) released the Oracle Critical Patch Update for July 2026, a quarterly bundle of 1,448 new security patches across Database, E-Business Suite, Fusion Middleware, PeopleSoft, JD Edwards and dozens of other products. CSO Online and Qualys counted 1,449.

E-Business Suite, Oracle's enterprise resource planning (ERP) suite for finance, supply chain and HR, took the largest share with 410 patches. Oracle rated 45 of them as remotely exploitable without authentication, meaning an attacker may not need a password. Fusion Middleware followed with 355 patches, 219 of them remotely exploitable without authentication, and Oracle Communications had 168. PeopleSoft received 84, Database products 72 and JD Edwards 20.

Severity is measured on the Common Vulnerability Scoring System (CVSS), a 0 to 10 scale. Oracle's Fusion Middleware risk matrix lists ten entries at 10.0, including flaws in Oracle Access Manager, Oracle WebCenter Content and the WebLogic Server Proxy Plug-in, all rated remotely exploitable without authentication. The highest-rated Database Server flaw, CVE-2026-61211 in the DBMS_CLOUD component, scored 9.9 but requires an authenticated user. In E-Business Suite, a 9.8-rated flaw in the Oracle Work in Process module is also rated remotely exploitable without authentication.

The release was much larger than its predecessors: CSO Online reported that Oracle's April 2026 update carried 481 patches and the July 2025 update 309. According to Qualys, about 86% of the July patches address non-Oracle CVEs, such as open-source components bundled inside Oracle products.

Oracle's advisory repeated a standing warning: it keeps receiving reports of attempts to exploit flaws it has already fixed, and in some cases attackers succeeded because customers had not applied available patches. The company told customers to stay on supported versions and "apply security patches without delay."

The advisory also reflected Oracle's newer monthly rhythm, stating that security patches are released on the third Tuesday of each month. Oracle began shipping Critical Security Patch Updates, smaller releases of high-priority fixes, on May 28, 2026, and schedules them for the months without a quarterly update.

The numbers

New security patches (Oracle count)
1,448
E-Business Suite patches
410 (45 remotely exploitable without authentication)
Fusion Middleware patches
355 (219 remotely exploitable without authentication)
Risk-matrix entries rated CVSS 10.0
10, all in Fusion Middleware
April 2026 update, per CSO Online
481 patches

Why CEOs should care

For CIOs running Oracle applications, a release this size is a capacity problem before it is a security problem. ERP patches often have to be tested against each company's customizations before they reach production, and 410 fixes in one suite can crowd out planned upgrades. Leaders should confirm that each Oracle estate has a funded, recurring patch window, now monthly rather than quarterly, and that the support contract covers the versions they actually run.

CISOs should rank the work, not just count it. Start with internet-facing middleware and anything remotely exploitable without a login, such as the 10.0-rated Fusion Middleware entries and the E-Business Suite Work in Process flaw. Sanchit Vir Gogia of Greyhound Research told CSO Online he recommends a tiered response: reachable vulnerabilities within 72 hours and the trusted core within ten days. Ask your team which Oracle systems are exposed to the internet today and how long patching each one takes.

Boards and audit committees should ask for Oracle patch status as a standing metric. Oracle's own advisory says attackers have succeeded in some cases because customers had not applied available patches, so a backlog of unapplied ERP patches is a measurable business risk.

The bigger picture

Oracle's ERP software had already been under attack in 2026. Google Threat Intelligence reported that the ShinyHunters extortion group exploited a PeopleSoft flaw, CVE-2026-35273, as a zero-day from May 27 to June 9, before Oracle issued a Security Alert on June 10. More than 100 organizations were notified, 68% of them in higher education, according to Google. Qualys's estimate that most July patches address non-Oracle components also shows how much third-party code ships inside enterprise suites, which widens what each customer must track.

What happened next

Oracle kept to the monthly schedule. On August 18, it released a Critical Security Patch Update with 943 new patches, 120 for E-Business Suite, and on September 15 another with 673, including 159 for E-Business Suite. On September 25, Google reported a renewed ShinyHunters campaign against PeopleSoft that slipped past web application firewall rules by encoding one character of the targeted web address. Google said it targeted organizations that had added firewall rules but had not applied Oracle's patch.

The next quarterly Critical Patch Update is scheduled for October 20, 2026, followed by a monthly release on November 17.

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

How this story was made. Researched from primary sources such as company announcements and filings, with the help of technology tools, fact-checked twice, and approved for publication by Hussein Mukhtar.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards · Report an error

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Weekdays, 6 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.

More in Cybersecurity