Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Oracle’s First 2026 CPU Delivers 337 New Security Patches

Posted on January 21, 2026January 21, 2026 By CWS

Oracle has launched 337 new safety patches for over 30 merchandise as a part of its first Vital Patch Replace (CPU) for 2026.

There seem like roughly 230 distinctive CVEs in Oracle’s January 2026 CPU advisory.

Greater than two dozen of the recent fixes resolve critical-severity vulnerabilities and over 235 patches deal with flaws which can be remotely exploitable with out authentication.

Roughly half a dozen patches deal with CVE-2025-66516 (CVSS rating of 10/10), a vital defect in Apache Tika that might result in XML Exterior Entity (XXE) injection assaults.

Impacting three modules of Apache Tika, the vulnerability will be exploited by inserting crafted XFA recordsdata inside PDF paperwork.

Oracle merchandise that obtained patches for the problem embrace Commerce, Communications, Development and Engineering, Fusion Middleware, and PeopleSoft.Commercial. Scroll to proceed studying.

As soon as once more, Oracle Communications obtained the most important variety of safety fixes, at 56. Of those 34 resolve bugs that may be exploited by distant, unauthenticated attackers.

Subsequent in line is Fusion Middleware, with 51 new safety patches, together with 47 for weaknesses that may be exploited remotely, with out authentication.

Monetary Companies Purposes obtained 38 new fixes (33 for remotely exploitable, unauthenticated points), whereas MySQL bought 20 patches (7 for flaws that may be exploited by distant, unauthenticated attackers).

This month, Siebel CRM, Retail Purposes, and Virtualization obtained 14 safety patches every, however the variety of points which can be remotely exploitable with out authentication differs (11, 10, and 1, respectively).

A major variety of fixes have been additionally rolled out for Hyperion (12 patches – 10 for remotely exploitable, unauthenticated vulnerabilities), PeopleSoft (12 – 10), Java SE (11 – 11), and Provide Chain (10 – 8).

Greater than two dozen Oracle merchandise obtained fewer than 10 new safety fixes, together with Development and Engineering (8 – 7), Analytics (8 – 6), E-Enterprise Suite (8 – 2), Commerce (7 – 6), JD Edwards (7 – 5), Database Server (7 – 2), HealthCare Purposes (6 – 6), Utilities Purposes (5 – 4), GoldenGate (5 – 3), and Well being Sciences Purposes (5 – 3).

Lots of the merchandise that have been up to date additionally obtained fixes for added flaws and non-exploitable bugs. For a number of merchandise, Oracle solely patched non-exploitable third-party CVEs.

On Tuesday, Oracle printed a safety bulletin describing 14 new safety patches for the Oracle Solaris Working System, together with 11 for bugs that may be exploited remotely, with out authentication.

Associated: Oracle Releases October 2025 Patches

Associated: Cisco Patches Vulnerability Exploited by Chinese language Hackers

Associated: Fortinet Patches Vital Vulnerabilities in FortiFone, FortiSIEM

Associated: SAP’s January 2026 Safety Updates Patch Vital Vulnerabilities

Security Week News Tags:CPU, Delivers, Oracles, Patches, Security

Post navigation

Previous Post: Exposure Assessment Platforms Signal a Shift in Focus
Next Post: Anthropic MCP Server Flaws Lead to Code Execution, Data Exposure

Related Posts

Google Confirms Workspace Accounts Also Hit in Salesforce–Salesloft Drift Data Theft Campaign Security Week News
364,000 Impacted by Data Breach at LexisNexis Risk Solutions Security Week News
AI Is Supercharging Phishing: Here’s How to Fight Back Security Week News
1.2 Million Impacted by WestJet Data Breach Security Week News
Former US Soldier Who Hacked AT&T and Verizon Pleads Guilty Security Week News
Nevada Ransomware Attack Started Months Before It Was Discovered, Per Report Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Anthropic MCP Server Flaws Lead to Code Execution, Data Exposure
  • Oracle’s First 2026 CPU Delivers 337 New Security Patches
  • Exposure Assessment Platforms Signal a Shift in Focus
  • Hackers Extensively Abuses Visual Studio Code to Execute Malicious Payloads on Victim System
  • Analysis of 6 Billion Passwords Shows Stagnant User Behavior

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Anthropic MCP Server Flaws Lead to Code Execution, Data Exposure
  • Oracle’s First 2026 CPU Delivers 337 New Security Patches
  • Exposure Assessment Platforms Signal a Shift in Focus
  • Hackers Extensively Abuses Visual Studio Code to Execute Malicious Payloads on Victim System
  • Analysis of 6 Billion Passwords Shows Stagnant User Behavior

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark