Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Oracle’s April 2026 Update Fixes 481 Security Flaws

Oracle’s April 2026 Update Fixes 481 Security Flaws

Posted on April 22, 2026 By CWS

Oracle has issued a substantial update, releasing 481 security patches as part of its April 2026 Critical Patch Update (CPU). This comprehensive update spans 28 product families and addresses over 300 vulnerabilities that could be exploited remotely without the need for authentication. Notably, around three dozen of these patches correct critical security flaws.

Details on Vulnerabilities and Patches

The recent update lists approximately 450 distinct Common Vulnerabilities and Exposures (CVEs) on Oracle’s CPU page. Of these, nearly 240 are detailed in the risk matrix tables. Additional CVEs have been addressed, including issues stemming from third-party software that are not directly exploitable within Oracle’s own products. Some CVEs have been patched across multiple Oracle offerings, while others received third-party fixes.

Key Product Families Affected

Oracle Communications saw the highest number of security updates, totaling 139 patches, with 93 targeting remotely exploitable vulnerabilities. Financial Services Applications followed with 75 new security fixes, 59 of which are for remote, unauthenticated issues. Fusion Middleware received 59 patches, with 46 addressing similar vulnerabilities.

Other notable updates include patches for MySQL (34 fixes, 3 critical), PeopleSoft (21, 7 critical), E-Business Suite (18, 8 critical), Analytics (15, 11 critical), Retail Applications (15, all critical), and Siebel CRM (14, 13 critical).

Additional Products and Historical Vulnerabilities

Several Oracle products received nearly a dozen patches each, such as Java SE (11 patches, 7 critical), GoldenGate (10, 7 critical), and Enterprise Manager (9, 8 critical). The update also covers vulnerabilities in products like Adapter for Eclipse RDF4J, Autonomous Health Framework, and Blockchain Platform, among others.

Approximately 390 vulnerabilities addressed in this update were publicly disclosed within the last two years. The remaining vulnerabilities trace back to earlier years, including five from as far back as 2020 and 2021.

This significant update follows Oracle’s emergency patch in March 2026 for a critical remote code execution flaw, CVE-2026-21992, in Identity Manager and Web Services Manager.

The April 2026 CPU highlights Oracle’s ongoing commitment to enhancing the security of its products and ensuring users are protected against evolving threats.

Security Week News Tags:April 2026, critical patch update, CVE, Cybersecurity, financial services, Fusion Middleware, Oracle, Oracle Communications, remote exploits, security patches, Software Security, software updates, technology news, Vulnerabilities

Post navigation

Previous Post: New LOTUSLITE Variant Targets Indian Banks and South Korean Policy
Next Post: Critical Flaws in Atlassian Bamboo Demand Urgent Patching

Related Posts

In Other News: ATM Jackpotting, WhatsApp-NSO Lawsuit Continues, CISA Hiring In Other News: ATM Jackpotting, WhatsApp-NSO Lawsuit Continues, CISA Hiring Security Week News
FBI Aware of 900 Organizations Hit by Play Ransomware FBI Aware of 900 Organizations Hit by Play Ransomware Security Week News
Man Who Hacked Organizations to Advertise Security Services Pleads Guilty Man Who Hacked Organizations to Advertise Security Services Pleads Guilty Security Week News
Patrick Ware Named Executive Director of US Cyber Command Patrick Ware Named Executive Director of US Cyber Command Security Week News
WhatsApp Boosts Account Security for At-Risk Individuals WhatsApp Boosts Account Security for At-Risk Individuals Security Week News
Axonius Acquires Medical Device Security Firm Cynerio in 0 Million Deal Axonius Acquires Medical Device Security Firm Cynerio in $100 Million Deal Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Google Antigravity Faces Security Threats Amid Growing Use
  • Critical Flaw in Terrarium Sandbox Allows Code Execution
  • Critical Flaws in Atlassian Bamboo Demand Urgent Patching
  • Oracle’s April 2026 Update Fixes 481 Security Flaws
  • New LOTUSLITE Variant Targets Indian Banks and South Korean Policy

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Google Antigravity Faces Security Threats Amid Growing Use
  • Critical Flaw in Terrarium Sandbox Allows Code Execution
  • Critical Flaws in Atlassian Bamboo Demand Urgent Patching
  • Oracle’s April 2026 Update Fixes 481 Security Flaws
  • New LOTUSLITE Variant Targets Indian Banks and South Korean Policy

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark