Oracle Releases Quarterly Critical Patch Update Addressing 1449 Vulnerabilities Across Numerous Products
Oracle has issued its regular quarterly Critical Patch Update on July 21, 2026, delivering fixes for a total of 1449 vulnerabilities. After removing duplicates, the update covers 1235 unique CVEs and impacts a broad range of products including Oracle Database Server, Oracle Java SE, Oracle MySQL, Oracle Fusion Middleware, Oracle WebLogic Server, and many others. Among the fixes, 261 vulnerabilities received CVSS base scores of 9.0 or higher, with ten rated at the maximum score of 10.0. Additionally, 1024 issues scored 7.0 or above, and 663 vulnerabilities can be exploited remotely without authentication. The advisory provides detailed guidance for administrators to apply the patches promptly across enterprise environments.
Security NEXT•Vulnerabilities & Exploits