Oracle released its first new monthly Critical Security Patch Update, fixing 77 vulnerabilities across several enterprise products used by businesses and public-sector organizations. The May 2026 update covers Oracle Database Server, REST Data Services, Communications, E-Business Suite, and Hospitality Applications, including about a dozen critical-severity flaws and multiple bugs that remote, unauthenticated attackers could exploit over a network. Oracle did not cite active exploitation in this notice but urged customers to patch quickly.
Why it matters: Organizations running affected Oracle software should treat this as a prompt patching event, especially where systems are internet-facing. Several flaws can be exploited remotely without logging in, so defenders should identify exposed Oracle services and apply the new updates as soon as possible.
2026.07.23
96% relevant
This article updates the same underlying Oracle patching initiative by reporting Oracle's July 2026 quarterly release of 1,449 security patches and noting the company's new model of supplementing quarterly Critical Patch Updates with monthly Critical Security Patch Updates introduced in May 2026.
Eduard Kovacs
2026.06.17
93% relevant
This article is a direct follow-up on the same underlying Oracle monthly patch program, adding that Oracle's second monthly Critical Security Patch Update for June 2026 fixes 245 vulnerabilities across Communications, E-Business Suite, Enterprise Manager, Fusion Middleware, JD Edwards, MySQL, PeopleSoft, Siebel CRM, Supply Chain, Systems, and Virtualization, including roughly 120 critical flaws and about 100 remotely exploitable without authentication.
Ionut Arghire
2026.06.02
100% relevant
This article establishes a distinct patching story: Oracle's launch of monthly CSPU releases and the first batch of 77 fixes affecting multiple Oracle product lines.
← Back to all stories