Skip to content
Beveiligingsnieuws

Oracle August 2026 Security Update: 943 Patches

943 oracle patches

Oracle has rolled out its August 2026 Critical Security Patch Update (CSPU), delivering 943 new security patches. This is the company’s third monthly security rollout, and the accompanying advisory indicates a large number of vulnerabilities across a wide range of products.

According to Oracle, the release covers more than 1,000 unique CVEs spanning two dozen products. Importantly, it also includes hundreds of issues that can be exploited remotely without authentication, plus a substantial subset rated critical.

What’s included in the Oracle August 2026 security update

Oracle’s advisory points to a broad scope: more than a thousand unique CVEs across dozens of offerings. In addition to fixes for multiple additional security flaws, the update addresses a particularly risky category—remote exploitation without needing authentication.

Oracle reports that over 460 vulnerabilities are remotely exploitable without authentication. The patch set also contains serious defects, with more than 150 security issues carrying critical severity. Nearly 90 of these have a CVSS score of 9.8 or higher, underscoring the urgency of remediation.

Remote, unauthenticated issues receive heavy attention

When vulnerabilities can be triggered from the network and do not require authentication, the attack surface effectively expands. Oracle’s August 2026 CSPU includes many fixes aimed at reducing exactly this kind of risk.

For organizations running the affected products, this is a key takeaway: these are not only theoretical weaknesses. The advisory signals a large number of remotely reachable problems that patching should prioritize.

Fusion Middleware and Hyperion lead patch volume

Two product lines received the largest number of new patches this month:

  • Fusion Middleware: 262 new patches
  • Hyperion: 262 new patches

Both updates include significant critical content. For Fusion Middleware, Oracle notes over 100 critical-severity flaws—specifically 80. For Hyperion, the critical count is 27.

Breakdown of remotely exploitable flaws

Oracle also provided details on the number of remotely exploitable, unauthenticated weaknesses handled in these major sections of the update:

  • Fusion Middleware resolves 182 bugs exploitable remotely without authentication.
  • Hyperion includes 107 patches addressing similar weaknesses.

That combination—high patch counts plus large volumes of remote, unauthenticated issues—makes these areas prime candidates for accelerated testing and deployment.

Other Oracle applications also see extensive fixes

Beyond Fusion Middleware and Hyperion, Oracle’s August 2026 CSPU includes many patches for business applications. The advisory lists notable volumes for:

  • E-Business Suite (120)
  • Commerce (66)
  • Siebel CRM (50)
  • Supply Chain (46)

These products often sit at the center of customer-facing and operational workflows. As a result, delays in remediation can create longer windows for attackers to test exposed services.

Broader ecosystem: databases, management tools, and more

The August update is not limited to a single stack. Oracle also released patches for a variety of additional products, including:

  • VM VirtualBox
  • Analytics
  • PeopleSoft
  • Communications
  • Enterprise Manager
  • MySQL
  • Financial Services Applications
  • Autonomous Health Framework
  • Application Testing Suite
  • JD Edwards
  • Database Server
  • Java SE
  • Retail Applications
  • Essbase
  • Food and Beverage Applications
  • Construction and Engineering
  • Hospitality Applications

Because organizations commonly mix components across these product families, it’s worth verifying which systems you run and mapping them to the advisory to avoid missed remediation.

How this compares to the previous month

Oracle’s August 2026 CSPU includes over 1,000 resolved security defects, which is a slightly smaller patch and vulnerability count than the July 2026 Critical Patch Update. Oracle’s July rollout included 1,449 security patches addressing over 1,400 unique CVEs.

While August is down compared with July, it still represents a very large set of changes. In practice, that means security teams should expect significant validation work—especially when critical and remotely exploitable issues are involved.

Why the patch volume remains so high

One explanation Oracle has tied to the growing frequency and scale of patching is the use of advanced AI-assisted vulnerability discovery. Oracle previously stated that it uses advanced LLM models to speed up the process of identifying vulnerabilities and producing patches.

In other words, the high count of vulnerabilities being resolved each month may reflect not only the pace of software development, but also improvements in how vulnerabilities are discovered and triaged.

Recommended actions for Oracle customers

Oracle advises customers to apply the security updates as soon as possible. The company notes that threat actors have been known to exploit vulnerabilities in Oracle products, and it has also received reports of attempts to maliciously target vulnerabilities for which patches have already been published.

If you support systems running any of the affected products, consider the following practical steps:

  • Confirm exposure: verify which Oracle products and versions you have in production.
  • Prioritize critical and remote issues: focus first on critical severity defects and those exploitable without authentication.
  • Plan validation: test patches in a staging environment, especially for Fusion Middleware and Hyperion where the volume is highest.
  • Deploy quickly: work from your patch windows, but avoid prolonged delays for externally reachable services.

Bottom line

The Oracle August 2026 security update brings 943 new security patches and resolves more than 1,000 unique CVEs across a broad portfolio of products. With hundreds of remotely exploitable, unauthenticated vulnerabilities and a large number of critical issues—including many with very high CVSS scores—this is a release that warrants prompt attention.

For security and IT teams, the key message is clear: fast patching, careful validation, and thorough coverage mapping will help reduce the risk that attackers move quickly to exploit newly disclosed weaknesses.

Source: https://www.securityweek.com/943-patches-rolled-out-with-oracles-august-2026-security-update/