← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Oracle Releases 943 Security Patches in August 2026 Critical Security Update

🔄 Updated 16h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • 943 new security patches released in August 2026 CSPU.
  • Addresses over 1,000 unique CVEs across 24 products.
  • Over 460 vulnerabilities are remotely exploitable without authentication.
  • More than 150 critical-severity bugs, nearly 90 with CVSS 9.8+.

Extensive Security Update Released

Oracle announced the release of 943 new security patches as part of its August 2026 Critical Security Patch Update (CSPU). This marks the company's third monthly security rollout, addressing a broad range of vulnerabilities across its product portfolio.

Scope of Vulnerabilities

The update covers more than 1,000 unique CVEs across two dozen Oracle products. A significant portion, over 460 vulnerabilities, can be exploited remotely without requiring authentication. Additionally, more than 150 of the identified security defects are critical-severity bugs, with nearly 90 of these having a CVSS score of 9.8 or higher.

Affected Products

Fusion Middleware and Hyperion received the largest number of new security patches, each with 262, including over 100 critical-severity flaws. Other products receiving substantial updates include E-Business Suite (120), Commerce (66), Siebel CRM (50), and Supply Chain (46). Fixes were also provided for VM VirtualBox, Analytics, PeopleSoft, Communications, Enterprise Manager, MySQL, and Java SE, among others.

Context and Impact

While substantial, the August 2026 CSPU's 1,000 resolved security defects are slightly fewer than the 1,449 patches released in the July 2026 Critical Patch Update. Oracle attributes the high volume of patches to its use of advanced LLM models for vulnerability discovery. Oracle advises customers to apply these security updates promptly due to known exploitation attempts of vulnerabilities in Oracle products.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~28 min · 23 stories · Aug 19

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Oracle has released 943 new security patches as part of its August 2026 Critical Security Patch Update, addressing over 1,000 unique CVEs across two dozen products. This update is significant because it includes over 460 remotely exploitable vulnerabilities without authentication, with more than 150 critical-severity bugs, necessitating prompt application by customers.