Oracle has rolled out its August 2026 Critical Security Patch Update (CSPU), delivering 943 new security patches. This is the company’s third monthly security rollout, and the accompanying advisory indicates a large number of vulnerabilities across a wide range of products.
According to Oracle, the release covers more than 1,000 unique CVEs spanning two dozen products. Importantly, it also includes hundreds of issues that can be exploited remotely without authentication, plus a substantial subset rated critical.
What’s included in the Oracle August 2026 security update
Oracle’s advisory points to a broad scope: more than a thousand unique CVEs across dozens of offerings. In addition to fixes for multiple additional security flaws, the update addresses a particularly risky category—remote exploitation without needing authentication.
Oracle reports that over 460 vulnerabilities are remotely exploitable without authentication. The patch set also contains serious defects, with more than 150 security issues carrying critical severity. Nearly 90 of these have a CVSS score of 9.8 or higher, underscoring the urgency of remediation.
Remote, unauthenticated issues receive heavy attention
When vulnerabilities can be triggered from the network and do not require authentication, the attack surface effectively expands. Oracle’s August 2026 CSPU includes many fixes aimed at reducing exactly this kind of risk.
For organizations running the affected products, this is a key takeaway: these are not only theoretical weaknesses. The advisory signals a large number of remotely reachable problems that patching should prioritize.
Fusion Middleware and Hyperion lead patch volume
Two product lines received the largest number of new patches this month:
- Fusion Middleware: 262 new patches
- Hyperion: 262 new patches
Both updates include significant critical content. For Fusion Middleware, Oracle notes over 100 critical-severity flaws—specifically 80. For Hyperion, the critical count is 27.
Breakdown of remotely exploitable flaws
Oracle also provided details on the number of remotely exploitable, unauthenticated weaknesses handled in these major sections of the update:
- Fusion Middleware resolves 182 bugs exploitable remotely without authentication.
- Hyperion includes 107 patches addressing similar weaknesses.
That combination—high patch counts plus large volumes of remote, unauthenticated issues—makes these areas prime candidates for accelerated testing and deployment.
Other Oracle applications also see extensive fixes
Beyond Fusion Middleware and Hyperion, Oracle’s August 2026 CSPU includes many patches for business applications. The advisory lists notable volumes for:
- E-Business Suite (120)
- Commerce (66)
- Siebel CRM (50)
- Supply Chain (46)
These products often sit at the center of customer-facing and operational workflows. As a result, delays in remediation can create longer windows for attackers to test exposed services.
Broader ecosystem: databases, management tools, and more
The August update is not limited to a single stack. Oracle also released patches for a variety of additional products, including:
- VM VirtualBox
- Analytics
- PeopleSoft
- Communications
- Enterprise Manager
- MySQL
- Financial Services Applications
- Autonomous Health Framework
- Application Testing Suite
- JD Edwards
- Database Server
- Java SE
- Retail Applications
- Essbase
- Food and Beverage Applications
- Construction and Engineering
- Hospitality Applications
Because organizations commonly mix components across these product families, it’s worth verifying which systems you run and mapping them to the advisory to avoid missed remediation.
How this compares to the previous month
Oracle’s August 2026 CSPU includes over 1,000 resolved security defects, which is a slightly smaller patch and vulnerability count than the July 2026 Critical Patch Update. Oracle’s July rollout included 1,449 security patches addressing over 1,400 unique CVEs.
While August is down compared with July, it still represents a very large set of changes. In practice, that means security teams should expect significant validation work—especially when critical and remotely exploitable issues are involved.
Why the patch volume remains so high
One explanation Oracle has tied to the growing frequency and scale of patching is the use of advanced AI-assisted vulnerability discovery. Oracle previously stated that it uses advanced LLM models to speed up the process of identifying vulnerabilities and producing patches.
In other words, the high count of vulnerabilities being resolved each month may reflect not only the pace of software development, but also improvements in how vulnerabilities are discovered and triaged.
Recommended actions for Oracle customers
Oracle advises customers to apply the security updates as soon as possible. The company notes that threat actors have been known to exploit vulnerabilities in Oracle products, and it has also received reports of attempts to maliciously target vulnerabilities for which patches have already been published.
If you support systems running any of the affected products, consider the following practical steps:
- Confirm exposure: verify which Oracle products and versions you have in production.
- Prioritize critical and remote issues: focus first on critical severity defects and those exploitable without authentication.
- Plan validation: test patches in a staging environment, especially for Fusion Middleware and Hyperion where the volume is highest.
- Deploy quickly: work from your patch windows, but avoid prolonged delays for externally reachable services.
Bottom line
The Oracle August 2026 security update brings 943 new security patches and resolves more than 1,000 unique CVEs across a broad portfolio of products. With hundreds of remotely exploitable, unauthenticated vulnerabilities and a large number of critical issues—including many with very high CVSS scores—this is a release that warrants prompt attention.
For security and IT teams, the key message is clear: fast patching, careful validation, and thorough coverage mapping will help reduce the risk that attackers move quickly to exploit newly disclosed weaknesses.
Source: https://www.securityweek.com/943-patches-rolled-out-with-oracles-august-2026-security-update/
