Aggregator
Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs
Oracle addresses 925 CVEs in its August 2026 Critical Security Patch Update with 943 patches, including 154 critical updates.
Key Takeaways- The August 2026 Critical Security Patch Update (CSPU) contains fixes for 925 unique CVEs in 943 security updates
- 154 issues (16.3% of all patches) were assigned a critical severity rating
- Oracle Fusion Middleware received the highest number of patches at 262, accounting for 27.8% of all patches
On August 18, Oracle released its Critical Security Patch Update (CSPU) for August 2026. Beginning in May 2026, Oracle introduced CSPUs as a monthly release cycle that sits between the larger quarterly Critical Patch Updates (CPUs), addressing a focused set of high-severity issues on a faster cadence. This CSPU contains fixes for 925 unique CVEs in 943 security updates across 23 Oracle product families, a nearly fourfold increase in patch volume compared to the June 2026 CSPU, which addressed 243 CVEs in 245 patches across 11 product families.
To put that in context against the quarterly CPUs: the April 2026 CPU contained 481 patches across 241 CVEs, and the July 2026 CPU, the largest CPU release of 2026, contained 1,449 patches across 1,235 CVEs. August's CSPU at 943 patches sits well above the April CPU and represents roughly 65% of July's quarterly volume, a striking figure for what is nominally a targeted between-cycle release. The expansion to 23 product families (up from 11 in June) further blurs the line between CSPU and CPU in terms of scope.
Out of the 943 security updates published, 16.3% of patches were assigned a critical severity. High severity patches accounted for the bulk of security patches at 59%, followed by medium severity patches at 21%.
This month's update includes 154 critical patches across 151 CVEs.
SeverityIssues PatchedCVEsCritical154151High556541Medium198198Low3535Total943925AnalysisThis month's update saw the Oracle Fusion Middleware product family contain the highest number of patches at 262, accounting for 27.8% of the total patches, followed by Oracle Hyperion at 262 patches, which accounted for 27.8% of the total patches.
A full breakdown of the patches for this CSPU can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication.
Oracle Product FamilyNumber of PatchesRemote Exploit without AuthOracle Fusion Middleware262182Oracle Hyperion262107Oracle E-Business Suite12027Oracle Commerce6647Oracle Siebel CRM5021Oracle Supply Chain4618Oracle Virtualization212Oracle Analytics163Oracle PeopleSoft157Oracle Communications139Oracle Enterprise Manager116Oracle MySQL95Oracle Financial Services Applications86Oracle Autonomous Health Framework72Oracle Application Testing Suite73Oracle Database Server64Oracle JD Edwards62Oracle Java SE54Oracle Retail Applications55Oracle Essbase43Oracle Food and Beverage Applications22Oracle Construction and Engineering11Oracle Hospitality Applications11SolutionPatches for all affected products are available in the August 2026 advisory.
Identifying affected systemsA list of Tenable plugins to identify these vulnerabilities will appear here as they're released. This link uses a search filter so that all matching plugin coverage appears as it is released.
Get more information- Oracle Critical Security Patch Update Advisory - August 2026
- Oracle August 2026 Critical Security Patch Update Risk Matrices
- Oracle Advisory to CVE Map
Join Tenable's Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.
Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.
苹果「摄像头耳机」曝光;小米机器人将亮相机器人大会;特斯拉与 SpaceX 合并预期升温 | 极客早知道
Weekly Report: 複数のマイクロソフト製品に脆弱性
关于国产大模型安全能力评估与跨网数据流动监控的探讨|总第319周
威努特工业网闸:破解石化行业生产安全与数据流转难题
JVN: CISA ICS Advisory / ICS Medical Advisory(2026年08月18日)
【通知】第六届开源情报技术大会拟于2026年11月贵阳召开
【开源报告】同样的意识形态领域事件,中国和越南处理结果大不一样
【AI复盘】伊朗黑客组织攻击美国水务系统
ChatGPT Ads expands across Europe
AirTag и SmartTag: как понять, что за вами следят через Bluetooth-трекер
Critical GitLab Zero-Click Flaw Poses Mitigation Challenges
OpenAI slows model development over concerns about cyber capabilities
OpenAI has temporarily slowed the development and scaling of its frontier AI models after determining that its existing monitoring, alignment, and security measures needed to be strengthened as models become increasingly capable of conducting cybersecurity tasks. The company said it deliberately reduced the pace of scaling while it worked to ensure that its safeguards could …
The post OpenAI slows model development over concerns about cyber capabilities appeared first on CyberInsider.
'CoSnitch' Attack Tricked Copilot Into Mapping Out Architecture
Eight years later, federal authorities re-up charges against alleged Iranian hackers at Mabna Institute
The superseding indictment adds defendants and allegations against the Iranian firm accused of a massive cybertheft campaign against foreign universities and others.
The post Eight years later, federal authorities re-up charges against alleged Iranian hackers at Mabna Institute appeared first on CyberScoop.