Oracle Critical Patch Update, August 2026 Security Update Review

Oracle released its August edition of Critical Patch Update. The update received patches for 943 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.

In this Oracle Critical Patch Update, Oracle Fusion Middleware and Oracle Hyperion received the highest number of patches, 262.

53 of the 943 (about 6%) security patches provided by the August Critical Patch Update are for non-Oracle CVEs, such as open-source components included in and exploitable within Oracle product distributions.

This batch of security patches received 17 updates for Oracle Database products. The following is the product-wise distribution:

  • 6 new security updates for Oracle Database Server with a maximum reported CVSS Base Score of 9.6.
      • None of these updates applies to client-only deployments of the Oracle Database.
  • 7 new security updates for Oracle Autonomous Health Framework with a maximum reported CVSS Base Score of 8.8.
  • 4 new security updates for Oracle Essbase with a maximum reported CVSS Base Score of 9.8.

In these security updates, Oracle has covered product families, including Oracle Database Server, Oracle Autonomous Health Framework, Oracle Essbase, Oracle Application Testing Suite, Oracle Commerce, Oracle Communications, Oracle Construction and Engineering, Oracle E-Business Suite, Oracle Enterprise Manager, Oracle Financial Services Applications, Oracle Food and Beverage Applications, Oracle Fusion Middleware, Oracle Analytics, Oracle Hospitality Applications, Oracle Hyperion, Oracle Java SE, Oracle JD Edwards, Oracle MySQL, Oracle PeopleSoft, Oracle Retail Applications, Oracle Siebel CRM, Oracle Supply Chain, Oracle Virtualization.

Notable Oracle Vulnerabilities Patched

Oracle Fusion Middleware

This Critical Patch Update for Oracle Fusion Middleware received 262 security patches. Out of these, 182 vulnerabilities can be exploited over a network without user credentials.

A total of 78 CVEs have critical severity ratings.

Oracle Hyperion

This Critical Patch Update for Oracle Hyperion received 262 security patches. Out of these, 107 vulnerabilities can be exploited over a network without user credentials.

A total of 27 CVEs have critical severity ratings.

Oracle E-Business Suite

This Critical Patch Update for Oracle E-Business Suite received 120 security patches. Out of these, 27 vulnerabilities can be exploited over a network without user credentials.

CVE-2026-60782 and CVE-2026-70926 have critical severity ratings with a CVSS score of 9.8. Successful exploitation of these vulnerabilities can lead to remote code execution.

Oracle Commerce

This Critical Patch Update for Oracle Commerce received 66 security patches. Out of these, 47 vulnerabilities can be exploited over a network without user credentials.

A total of 18 CVEs have critical severity ratings.

Oracle Siebel CRM

This Critical Patch Update for Oracle Siebel CRM received 50 security patches. Out of these, 21 vulnerabilities can be exploited over a network without user credentials.

A total of 10 CVEs have critical severity ratings.

Visit the Oracle Critical Patch Update August 2026 (CPUAUG2026) page to read descriptions of each vulnerability and the systems it affects.

Customers can scan their network with QIDs 87617, 388370, 388371, 388372, and 20609 to detect vulnerable assets.

Please continue to follow Qualys Threat Protection for more coverage of the latest vulnerabilities.

References:
https://www.oracle.com/security-alerts/cspuaug2026.html