Updated
Updated · InfoWorld · Jul 22
Oracle Fixes 1,449 Flaws in July Update as 10 Fusion Middleware Bugs Hit 10.0
Updated
Updated · InfoWorld · Jul 22

Oracle Fixes 1,449 Flaws in July Update as 10 Fusion Middleware Bugs Hit 10.0

3 articles · Updated · InfoWorld · Jul 22

Summary

  • Oracle’s July 2026 Critical Patch Update—its largest ever—delivers 1,449 security fixes across 32 product families, with Fusion Middleware alone accounting for 355 vulnerabilities and 219 remotely exploitable without authentication.
  • Ten Fusion Middleware flaws carried a maximum 10.0 CVSS score, affecting products including Oracle Data Integrator, Access Manager, HTTP Server, WebCenter Content and WebLogic Server Proxy Plug-in via unauthenticated HTTP-based attacks.
  • Oracle Database Server also received urgent fixes, led by CVE-2026-61211, a 9.9-rated DBMS_CLOUD flaw that can let a low-privileged attacker take over exposed RDBMS instances; a second bug in Oracle Net Services is remotely exploitable without credentials.
  • Patch volume has surged from 481 in April and 309 a year earlier, prompting analysts to urge triage within 72 hours for internet-reachable systems rather than patching by product name alone.
  • The release is Oracle’s third quarterly CPU of 2026 and follows its new monthly security-patch program, with the next updates scheduled for Aug. 18, Sept. 15 and Oct. 20.

Insights

Is Oracle’s record patch release a security triumph, or a sign its software was dangerously insecure until now?
With patch volume tripling, can companies afford the operational costs of Oracle's new AI-powered security strategy?

Oracle’s July 2026 CPU Breaks Record: Over 1,000 Vulnerabilities Patched Amid AI-Accelerated Threats

Overview

Oracle's July 2026 Critical Patch Update marks an unprecedented security event, driven by a dramatic acceleration in vulnerability discovery and exploit development fueled by advanced AI systems. This update is a direct response to machine-speed vulnerability hunting, where AI scans vast codebases, finds subtle weaknesses, and validates their exploitability. As a result, Oracle patched a record number of issues across its product lines, with the Oracle E-Business Suite receiving the largest number of patches. The sheer volume of vulnerabilities highlights the urgent need for organizations to adapt their security strategies to this new, AI-driven threat landscape.

...