Oracle announced the release of 943 new security patches as part of its August 2026 Critical Security Patch Update (CSPU). This marks the company's third monthly security rollout, addressing a broad range of vulnerabilities across its product portfolio.
The update covers more than 1,000 unique CVEs across two dozen Oracle products. A significant portion, over 460 vulnerabilities, can be exploited remotely without requiring authentication. Additionally, more than 150 of the identified security defects are critical-severity bugs, with nearly 90 of these having a CVSS score of 9.8 or higher.
Fusion Middleware and Hyperion received the largest number of new security patches, each with 262, including over 100 critical-severity flaws. Other products receiving substantial updates include E-Business Suite (120), Commerce (66), Siebel CRM (50), and Supply Chain (46). Fixes were also provided for VM VirtualBox, Analytics, PeopleSoft, Communications, Enterprise Manager, MySQL, and Java SE, among others.
While substantial, the August 2026 CSPU's 1,000 resolved security defects are slightly fewer than the 1,449 patches released in the July 2026 Critical Patch Update. Oracle attributes the high volume of patches to its use of advanced LLM models for vulnerability discovery. Oracle advises customers to apply these security updates promptly due to known exploitation attempts of vulnerabilities in Oracle products.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Oracle has released 943 new security patches as part of its August 2026 Critical Security Patch Update, addressing over 1,000 unique CVEs across two dozen products. This update is significant because it includes over 460 remotely exploitable vulnerabilities without authentication, with more than 150 critical-severity bugs, necessitating prompt application by customers.