Oracle Fixes 1,449 Flaws in July Update as 10 Fusion Middleware Bugs Hit 10.0
Updated
Updated · InfoWorld · Jul 22
Oracle Fixes 1,449 Flaws in July Update as 10 Fusion Middleware Bugs Hit 10.0
3 articles · Updated · InfoWorld · Jul 22
Summary
Oracle’s July 2026 Critical Patch Update—its largest ever—delivers 1,449 security fixes across 32 product families, with Fusion Middleware alone accounting for 355 vulnerabilities and 219 remotely exploitable without authentication.
Ten Fusion Middleware flaws carried a maximum 10.0 CVSS score, affecting products including Oracle Data Integrator, Access Manager, HTTP Server, WebCenter Content and WebLogic Server Proxy Plug-in via unauthenticated HTTP-based attacks.
Oracle Database Server also received urgent fixes, led by CVE-2026-61211, a 9.9-rated DBMS_CLOUD flaw that can let a low-privileged attacker take over exposed RDBMS instances; a second bug in Oracle Net Services is remotely exploitable without credentials.
Patch volume has surged from 481 in April and 309 a year earlier, prompting analysts to urge triage within 72 hours for internet-reachable systems rather than patching by product name alone.
The release is Oracle’s third quarterly CPU of 2026 and follows its new monthly security-patch program, with the next updates scheduled for Aug. 18, Sept. 15 and Oct. 20.
Is Oracle’s record patch release a security triumph, or a sign its software was dangerously insecure until now?
With patch volume tripling, can companies afford the operational costs of Oracle's new AI-powered security strategy?
Oracle’s July 2026 CPU Breaks Record: Over 1,000 Vulnerabilities Patched Amid AI-Accelerated Threats
Overview
Oracle's July 2026 Critical Patch Update marks an unprecedented security event, driven by a dramatic acceleration in vulnerability discovery and exploit development fueled by advanced AI systems. This update is a direct response to machine-speed vulnerability hunting, where AI scans vast codebases, finds subtle weaknesses, and validates their exploitability. As a result, Oracle patched a record number of issues across its product lines, with the Oracle E-Business Suite receiving the largest number of patches. The sheer volume of vulnerabilities highlights the urgent need for organizations to adapt their security strategies to this new, AI-driven threat landscape.