Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Oracle’s First 2026 CPU Delivers 337 New Security Patches

Oracle’s First 2026 CPU Delivers 337 New Security Patches

Posted on January 21, 2026January 21, 2026 By CWS

Oracle has launched 337 new safety patches for over 30 merchandise as a part of its first Vital Patch Replace (CPU) for 2026.

There seem like roughly 230 distinctive CVEs in Oracle’s January 2026 CPU advisory.

Greater than two dozen of the recent fixes resolve critical-severity vulnerabilities and over 235 patches deal with flaws which can be remotely exploitable with out authentication.

Roughly half a dozen patches deal with CVE-2025-66516 (CVSS rating of 10/10), a vital defect in Apache Tika that might result in XML Exterior Entity (XXE) injection assaults.

Impacting three modules of Apache Tika, the vulnerability will be exploited by inserting crafted XFA recordsdata inside PDF paperwork.

Oracle merchandise that obtained patches for the problem embrace Commerce, Communications, Development and Engineering, Fusion Middleware, and PeopleSoft.Commercial. Scroll to proceed studying.

As soon as once more, Oracle Communications obtained the most important variety of safety fixes, at 56. Of those 34 resolve bugs that may be exploited by distant, unauthenticated attackers.

Subsequent in line is Fusion Middleware, with 51 new safety patches, together with 47 for weaknesses that may be exploited remotely, with out authentication.

Monetary Companies Purposes obtained 38 new fixes (33 for remotely exploitable, unauthenticated points), whereas MySQL bought 20 patches (7 for flaws that may be exploited by distant, unauthenticated attackers).

This month, Siebel CRM, Retail Purposes, and Virtualization obtained 14 safety patches every, however the variety of points which can be remotely exploitable with out authentication differs (11, 10, and 1, respectively).

A major variety of fixes have been additionally rolled out for Hyperion (12 patches – 10 for remotely exploitable, unauthenticated vulnerabilities), PeopleSoft (12 – 10), Java SE (11 – 11), and Provide Chain (10 – 8).

Greater than two dozen Oracle merchandise obtained fewer than 10 new safety fixes, together with Development and Engineering (8 – 7), Analytics (8 – 6), E-Enterprise Suite (8 – 2), Commerce (7 – 6), JD Edwards (7 – 5), Database Server (7 – 2), HealthCare Purposes (6 – 6), Utilities Purposes (5 – 4), GoldenGate (5 – 3), and Well being Sciences Purposes (5 – 3).

Lots of the merchandise that have been up to date additionally obtained fixes for added flaws and non-exploitable bugs. For a number of merchandise, Oracle solely patched non-exploitable third-party CVEs.

On Tuesday, Oracle printed a safety bulletin describing 14 new safety patches for the Oracle Solaris Working System, together with 11 for bugs that may be exploited remotely, with out authentication.

Associated: Oracle Releases October 2025 Patches

Associated: Cisco Patches Vulnerability Exploited by Chinese language Hackers

Associated: Fortinet Patches Vital Vulnerabilities in FortiFone, FortiSIEM

Associated: SAP’s January 2026 Safety Updates Patch Vital Vulnerabilities

Security Week News Tags:CPU, Delivers, Oracles, Patches, Security

Post navigation

Previous Post: Exposure Assessment Platforms Signal a Shift in Focus
Next Post: Anthropic MCP Server Flaws Lead to Code Execution, Data Exposure

Related Posts

Anthropic MCP Server Flaws Lead to Code Execution, Data Exposure Anthropic MCP Server Flaws Lead to Code Execution, Data Exposure Security Week News
Telecom Giant Orange Hit by Cyberattack Telecom Giant Orange Hit by Cyberattack Security Week News
Cybersecurity M&A Roundup: 40 Deals Announced in September 2025 Cybersecurity M&A Roundup: 40 Deals Announced in September 2025 Security Week News
Fresh MongoDB Vulnerability Exploited in Attacks Fresh MongoDB Vulnerability Exploited in Attacks Security Week News
BadCam: New BadUSB Attack Turns Linux Webcams Into Persistent Threats  BadCam: New BadUSB Attack Turns Linux Webcams Into Persistent Threats  Security Week News
British Department Store Harrods Warns Customers That Some Personal Details Taken in Data Breach British Department Store Harrods Warns Customers That Some Personal Details Taken in Data Breach Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Top Log Monitoring Tools to Watch in 2026
  • Top Spam Filter Tools for 2026: A Comprehensive Guide
  • Top Fraud Detection Tools for 2026
  • Microsoft Urges Action on Critical Windows Updates
  • Citrix NetScaler Threat: Immediate Action Required

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Top Log Monitoring Tools to Watch in 2026
  • Top Spam Filter Tools for 2026: A Comprehensive Guide
  • Top Fraud Detection Tools for 2026
  • Microsoft Urges Action on Critical Windows Updates
  • Citrix NetScaler Threat: Immediate Action Required

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark