Oracle July 2026 Critical Patch Update (CPU)

Oracle Announces July 2026 Critical Patch Update with 1,455 Fixes

HIGH
July 20, 2026
4m read
Patch ManagementVulnerability

Related Entities

Organizations

Products & Tech

Oracle CommunicationsOracle AnalyticsOracle BI PublisherOracle Business Intelligence Enterprise EditionOracle APEXOracle Autonomous Health FrameworkOracle Database

Other

OpenAI

Full Report

Executive Summary

Oracle has published a pre-release announcement for its July 2026 Critical Patch Update (CPU), set for release on July 21, 2026. The update is one of the largest on record, with a staggering 1,455 new security patches addressing vulnerabilities across hundreds of Oracle products. A significant number of these flaws are remotely exploitable without authentication, posing a severe risk to unpatched systems. Notably, the update includes a fix for a vulnerability in Oracle Analytics products with a CVSS v3.1 base score of 9.9. Given the scale and severity of the vulnerabilities, Oracle is strongly advising all customers to prepare for immediate testing and deployment of the patches upon release.


Vulnerabilities Addressed

While the full list of CVEs will be released with the official advisory, the pre-announcement highlights several critical areas. The update addresses a wide range of vulnerability types, including those that allow for remote code execution, privilege escalation, and data theft.

Key product families and the number of patches they are receiving include:

  • Oracle Communications: 168 new patches (122 remotely exploitable without authentication)
  • Oracle Analytics: 6 new patches (4 remotely exploitable, one with a CVSS score of 9.9)
  • Oracle Autonomous Health Framework: 4 new patches (3 remotely exploitable, one with a CVSS score of 8.1)
  • Oracle APEX: 3 new patches (2 remotely exploitable)

Many other products, including the flagship Oracle Database and Oracle AI Database 26ai, will also receive critical updates.


Affected Products

The patch update covers a vast portfolio of Oracle software. Based on the pre-announcement, some of the key affected products include:

  • Oracle Communications Suite
  • Oracle Analytics
  • Oracle BI Publisher
  • Oracle Business Intelligence Enterprise Edition
  • Oracle Autonomous Health Framework
  • Oracle Application Express (APEX)
  • Oracle Database (multiple versions, including 19c)
  • Oracle AI Database 26ai
  • Oracle E-Business Suite
  • Oracle PeopleSoft
  • Oracle Siebel CRM
  • Oracle Fusion Middleware
  • Java SE

Customers should consult the final advisory on July 21 for a complete list of affected products and versions.


Impact Assessment

The sheer number of patches, especially those for remotely exploitable vulnerabilities, indicates a significant risk for organizations using Oracle products. A CVSS 9.9 vulnerability, like the one in Oracle Analytics, implies that an unauthenticated attacker on the network could potentially take full control of the affected system with low complexity.

Failure to apply these patches in a timely manner could expose organizations to:

  • Remote Code Execution: Attackers could gain control of critical database and application servers.
  • Data Breach: Vulnerabilities could be exploited to steal sensitive corporate, financial, or customer data.
  • Denial of Service: Exploitation could lead to the disruption of critical business applications and services.
  • Compliance Violations: Failure to patch known critical vulnerabilities can lead to non-compliance with regulations like PCI DSS and GDPR.

Deployment Priority

Given the critical nature of many of the patches, organizations should adopt a risk-based prioritization strategy:

  1. Internet-Facing Systems: Prioritize patching all Oracle products that are exposed to the internet, such as web applications built on APEX or Oracle Fusion Middleware. These are the most likely targets.
  2. Critical Data Systems: Systems hosting critical data, such as Oracle Databases and Oracle Analytics platforms, should be next. The flaw with the 9.9 CVSS score makes these a top priority.
  3. Internal Systems: Patch remaining internal systems based on their criticality and exposure.

It is crucial to test patches in a non-production environment before deploying them to production to avoid unforeseen operational issues.


Installation Instructions

Oracle will provide detailed installation instructions with the official CPU release on July 21, 2026. Customers should download the patches from My Oracle Support. The company's blog post emphasizes the need to keep database releases current and to apply this update immediately upon availability. This is a direct application of the D3FEND technique D3-SU: Software Update.


Cyber Observables — Hunting Hints

The following indicators could help identify unpatched systems or active exploitation attempts post-patch release:

Type
Port
Value
1521 (default)
Description
Monitor for unusual or unauthorized connection attempts to the Oracle Database listener port from unexpected sources.
Type
URL Pattern
Value
/xmlpserver
Description
This is the default URL for Oracle BI Publisher (part of Analytics). Monitor for anomalous requests to this path.
Type
Process Name
Value
oracle.exe (Windows), oracle (Linux)
Description
Look for unexpected child processes or crashes related to the main Oracle database process.
Type
Log Source
Value
Oracle Audit Logs
Description
Review Oracle's unified audit trail for failed login attempts, privilege escalations, or access to sensitive tables from unusual user accounts.

Timeline of Events

1
July 20, 2026
Oracle publishes the pre-release announcement for the July 2026 CPU.
2
July 20, 2026
This article was published
3
July 21, 2026
Scheduled release date for the Oracle July 2026 Critical Patch Update.

MITRE ATT&CK Mitigations

Applying the Critical Patch Update is the only way to remediate the 1,455 vulnerabilities being addressed.

Mapped D3FEND Techniques:

D3FEND Defensive Countermeasures

Organizations using Oracle products must treat the July 2026 CPU as an emergency change event. The sheer volume of patches (1,455) and the presence of critical, remotely exploitable flaws like the CVSS 9.9 vulnerability in Oracle Analytics, necessitates immediate action. The patching process should be risk-based: 1) Identify all Oracle assets in the environment. 2) Prioritize internet-facing systems (e.g., APEX, Fusion Middleware) for immediate patching. 3) Prioritize systems holding critical data (e.g., Oracle Database, Oracle Analytics) next. 4) Test patches in a dedicated staging environment that mirrors production to identify any potential operational impacts. 5) Deploy the patches to production as quickly as the testing cycle allows. Deferring this update introduces an unacceptable level of risk.

Timeline of Events

1
July 20, 2026

Oracle publishes the pre-release announcement for the July 2026 CPU.

2
July 21, 2026

Scheduled release date for the Oracle July 2026 Critical Patch Update.

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

OraclePatch TuesdayCPUVulnerabilityDatabase SecurityPatch Management

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.