Oracle’s August 2026 Critical Security Patch Update fixes more than 1,000 vulnerabilities across Fusion Middleware, E-Business Suite, MySQL, Java and other products

Oracle released 943 security patches in its August 2026 Critical Security Patch Update, affecting two dozen Oracle product lines used by businesses and governments. Oracle says the update addresses more than 1,000 unique CVEs, including over 460 flaws that can be exploited remotely without authentication and more than 150 critical-severity bugs. The largest patch groups hit Fusion Middleware and Hyperion, with additional fixes for E-Business Suite, Commerce, Siebel CRM, Supply Chain, MySQL, Java SE, Database Server, PeopleSoft, and other products.
Why it matters: Organizations running Oracle software may be exposed to serious break-in risk if they delay patching, especially on internet-facing systems. Admins should urgently inventory affected Oracle products, prioritize remotely exploitable and critical flaws, and apply the August 2026 updates as soon as possible.

Sources

943 Patches Rolled Out With Oracle’s August 2026 Security Update
Ionut Arghire 2026.08.19 100% relevant
This article establishes a new monthly Oracle patch-cycle event for August 2026, distinct from the already tracked July 2026 Oracle Critical Patch Update.
← Back to all stories