Oracle has announced the deployment of 943 security patches in its August 2026 Critical Security Patch Update (CSPU). This marks the third security update issued by the company this year.
Overview of Security Vulnerabilities
This month’s advisory highlights more than 1,000 unique Common Vulnerabilities and Exposures (CVEs) across approximately 24 Oracle products. Notably, over 460 of these vulnerabilities can be exploited remotely without requiring user authentication. The update addresses a variety of security flaws across the affected products.
High-Severity Vulnerabilities Targeted
Among the vulnerabilities, over 150 are classified as critical, with close to 90 boasting a Common Vulnerability Scoring System (CVSS) score of 9.8 or higher. These high-severity issues necessitate immediate attention from users and administrators to mitigate potential risks.
Fusion Middleware and Hyperion received significant updates, each with 262 new patches, including more than 100 critical vulnerabilities. Specifically, the Fusion Middleware update resolves 182 remotely exploitable bugs, while Hyperion addresses 107 such issues.
Comprehensive Product Updates
In addition to Fusion Middleware and Hyperion, Oracle released numerous patches for other key products. The E-Business Suite received 120 patches, Commerce 66, Siebel CRM 50, and Supply Chain 46. Other products that saw updates include VM VirtualBox, Analytics, PeopleSoft, Enterprise Manager, and MySQL, among others.
With a total of over 1,000 vulnerabilities addressed, the August update is slightly smaller than the July 2026 release, which included 1,449 patches.
Future Outlook and Recommendations
The substantial number of patches released is likely due to Oracle’s integration of advanced artificial intelligence (AI) technologies for faster vulnerability discovery and remediation. Earlier this year, Oracle mentioned using sophisticated language models to enhance their patching processes.
Oracle advises its customers to promptly apply these updates to safeguard against exploitation. The company has received reports of attempts to exploit vulnerabilities even after patches have been made available.
By staying vigilant and ensuring timely updates, organizations can protect themselves from potential cyber threats targeting Oracle products.
