Oracle Critical Security Patch Update August 2026

Oracle addresses 925 CVEs in its August 2026 Critical Security Patch Update with 943 patches, including 154 critical updates.

Key Takeaways

  1. The August 2026 Critical Security Patch Update (CSPU) contains fixes for 925 unique CVEs in 943 security updates
  2. 154 issues (16.3% of all patches) were assigned a critical severity rating
  3. Oracle Fusion Middleware received the highest number of patches at 262, accounting for 27.8% of all patches

Background

On August 18, Oracle released its Critical Security Patch Update (CSPU) for August 2026. Beginning in May 2026, Oracle introduced CSPUs as a monthly release cycle that sits between the larger quarterly Critical Patch Updates (CPUs), addressing a focused set of high-severity issues on a faster cadence. This CSPU contains fixes for 925 unique CVEs in 943 security updates across 23 Oracle product families, a nearly fourfold increase in patch volume compared to the June 2026 CSPU, which addressed 243 CVEs in 245 patches across 11 product families.

To put that in context against the quarterly CPUs: the April 2026 CPU contained 481 patches across 241 CVEs, and the July 2026 CPU, the largest CPU release of 2026, contained 1,449 patches across 1,235 CVEs. August’s CSPU at 943 patches sits well above the April CPU and represents roughly 65% of July’s quarterly volume, a striking figure for what is nominally a targeted between-cycle release. The expansion to 23 product families (up from 11 in June) further blurs the line between CSPU and CPU in terms of scope.

Pie chart showing the count of patches released in the Oracle August 2026 Critical Security Patch Update (CSPU)

Out of the 943 security updates published, 16.3% of patches were assigned a critical severity. High severity patches accounted for the bulk of security patches at 59%, followed by medium severity patches at 21%.

This month’s update includes 154 critical patches across 151 CVEs.

Severity Issues Patched CVEs
Critical 154 151
High 556 541
Medium 198 198
Low 35 35
Total 943 925

Analysis

This month’s update saw the Oracle Fusion Middleware product family contain the highest number of patches at 262, accounting for 27.8% of the total patches, followed by Oracle Hyperion at 262 patches, which accounted for 27.8% of the total patches.

A full breakdown of the patches for this CSPU can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication.

Oracle Product Family Number of Patches Remote Exploit without Auth
Oracle Fusion Middleware 262 182
Oracle Hyperion 262 107
Oracle E-Business Suite 120 27
Oracle Commerce 66 47
Oracle Siebel CRM 50 21
Oracle Supply Chain 46 18
Oracle Virtualization 21 2
Oracle Analytics 16 3
Oracle PeopleSoft 15 7
Oracle Communications 13 9
Oracle Enterprise Manager 11 6
Oracle MySQL 9 5
Oracle Financial Services Applications 8 6
Oracle Autonomous Health Framework 7 2
Oracle Application Testing Suite 7 3
Oracle Database Server 6 4
Oracle JD Edwards 6 2
Oracle Java SE 5 4
Oracle Retail Applications 5 5
Oracle Essbase 4 3
Oracle Food and Beverage Applications 2 2
Oracle Construction and Engineering 1 1
Oracle Hospitality Applications 1 1

Solution

Patches for all affected products are available in the August 2026 advisory.

Identifying affected systems

A list of Tenable plugins to identify these vulnerabilities will appear here as they’re released. This link uses a search filter so that all matching plugin coverage appears as it is released.

Get more information

Join Tenable’s Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.

Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.

Similar Posts

Leave a Reply