Oracle July 2026 CPU: largest ever, 1,449 patches
Oracle shipped its largest-ever Critical Patch Update: 1,449 fixes for 1,434 distinct CVEs across 334 products, including several critical flaws — patch now.
On July 21, 2026, Oracle released its quarterly Critical Patch Update (CPU) and called it the company's largest security release to date. Oracle attributes the scale to expanded product coverage, accelerated security-engineering processes, and AI-powered identification of actionable findings.
Key points
- 1,449 security patches addressing 1,434 distinct CVEs across 334 Oracle products.
- Affects core product families: Oracle Database Server, Java SE, MySQL, Fusion Middleware (WebLogic), E-Business Suite, PeopleSoft, JD Edwards, Siebel CRM, Communications and many industry applications.
- Oracle urges installing the update promptly and moving to a monthly patching cadence (CPUs ship on the third Tuesday each month).
- Full CVE details and risk matrices are in the official advisory; an executive summary is on My Oracle Support (Doc ID CPU160).
For organizations running Oracle systems, this is a priority round: the sheer size means a wide attack surface, so review and schedule patching early.
Source
Oracle
#Oracle#Security#CVE#Patch Update#Database
This summary was written by the ORA·tech AI assistant. Read the original for full context.
Related
Security & DevSecOps
Microsoft launches Project Perception agentic security system
Security & DevSecOps
Check Point CVE-2026-16232: SmartConsole auth bypass exploited
Security & DevSecOps
