Oracle Critical Patch Update, July 2026 Security Update Review

Oracle released its third quarterly edition of this year’s Critical Patch Update. The update received patches for 1449 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.

In this quarterly Oracle Critical Patch Update, Oracle E-Business Suite received the highest number of patches, 410, constituting about 28% of the total patches released.

1235 of the 1449 (about 86%) security patches provided by the July Critical Patch Update are for non-Oracle CVEs, such as open-source components included in and exploitable within Oracle product distributions.

This batch of security patches received 72 updates for Oracle Database products. The following is the product-wise distribution:

  • 15 new security updates for Oracle Database Server with a maximum reported CVSS Base Score of 9.9. 
      • Three of these updates apply to client-only deployments of the Oracle Database. 
  • Three new security updates for Oracle APEX with a maximum reported CVSS Base Score of 5.5. 
  • Four new security updates for the Oracle Autonomous Health Framework with a maximum reported CVSS Base Score of 8.1. 
  • One new security update for Oracle Essbase with a reported CVSS Base Score of 4.8. 
  • One new security update for Oracle Global Lifecycle Management has a reported CVSS Base Score of 8.1. 
  • 27 new security updates for Oracle GoldenGate with a maximum reported CVSS Base Score of 9.1. 
  • No new security updates for Oracle Graph Server and Client, but third-party patches are provided. 
  • One new security update for Oracle NoSQL Database. 
  • One new security update for Oracle Spatial Studio. 
  • Five new security updates for Oracle SQL Developer, all remotely exploitable without authentication (max CVSS not yet verified).
  • 14 new security updates for Oracle TimesTen In-Memory Database, four of which are remotely exploitable without authentication.

In these security updates, Oracle has covered product families, including Oracle E-Business Suite, Oracle Fusion Middleware, Oracle Communications, Oracle PeopleSoft, Oracle Database Products, Oracle MySQL, Oracle Siebel CRM, Oracle Commerce, Oracle Supply Chain, Oracle Financial Services Applications, Oracle Analytics, Oracle Application Testing Suite, Oracle Construction and Engineering (Primavera), Oracle Enterprise Manager, Oracle Food and Beverage Applications (Hospitality Simphony), Oracle Health Sciences / HealthCare Applications, Oracle Hospitality (Cruise SPMS), Oracle Java SE, Oracle JD Edwards, Oracle Retail Applications, Oracle Systems (Solaris), and Oracle Virtualization (VM VirtualBox).

Notable Oracle Vulnerabilities Patched

Oracle E-Business Suite

This Critical Patch Update for Oracle E-Business Suite received 410 security patches. Out of these, 45 vulnerabilities can be exploited over a network without user credentials.

CVE-2026-60880, CVE-2026-60773, CVE-2026-62549, and CVE-2026-62546 have critical severity ratings. Successful exploitation of these vulnerabilities can lead to remote code execution.

Oracle Fusion Middleware

This Critical Patch Update for Oracle Fusion Middleware received 355 security patches. Out of these, 219 vulnerabilities can be exploited over a network without user credentials.

A total of 154 CVEs have critical severity ratings. Successful exploitation of these vulnerabilities can lead to remote code execution.

Oracle Communications

This Critical Patch Update for Oracle Communications received 168 security patches. Out of these, 122 vulnerabilities can be exploited over a network without user credentials.

A total of 13 CVEs have critical severity ratings. Successful exploitation of these vulnerabilities can lead to remote code execution.

Oracle PeopleSoft

This Critical Patch Update for Oracle PeopleSoft received 84 security patches. Out of these, 45 vulnerabilities can be exploited over a network without user credentials.

A total of 17 CVEs have critical severity ratings. Successful exploitation of these vulnerabilities can lead to remote code execution.

Oracle MySQL

This Critical Patch Update for Oracle MySQL received 54 security patches. Out of these, nine vulnerabilities can be exploited over a network without user credentials.

None of the CVEs has a critical severity rating.

Visit the Oracle Critical Patch Update June 2026 (CPUJUL2026) page to describe each vulnerability and the systems it affects.

Customers can scan their network with QIDs 388003, 387986, 387988, 387996, 296138, 87614, 20599, 20600, and 20601 to detect vulnerable assets.

Please continue to follow Qualys Threat Protection for more coverage of the latest vulnerabilities.

References:
https://www.oracle.com/security-alerts/cpujul2026.html