[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f4HXm_e3xFsdHpP7e_F69BUAh_DPJcrTeWHEIjqlslPU":3},{"article":4,"iocs":40},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"36fa40ec-6425-48cf-8232-82b5cbab404f","Oracle Critical Patch Update, August 2026 Security Update Review","oracle-critical-patch-update-august-2026-security-update-review-3fdd7b","Oracle released its August edition of Critical Patch Update. The update received patches for 943 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products. In this Oracle Critical Patch Update, Oracle Fusion Middleware and Oracle Hyperion received the highest number of patches, 262. […]","Oracle has issued its August Critical Patch Update, patching a significant 943 security vulnerabilities. The update covers a wide range of Oracle products, with Oracle Fusion Middleware and Oracle Hyperion receiving the largest number of fixes (262 each). Notably, approximately 6% of the patches address vulnerabilities in third-party and open-source components integrated into Oracle products. Several vulnerabilities, particularly in Oracle E-Business Suite, carry critical severity ratings and can be exploited remotely without authentication, potentially leading to remote code execution.","Oracle released its August Critical Patch Update, addressing 943 security vulnerabilities across its product suite.","Table of ContentsQualys QID CoverageNotable Oracle Vulnerabilities Patched Oracle released its August edition of Critical Patch Update. The update received patches for 943 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products. In this Oracle Critical Patch Update, Oracle Fusion Middleware and Oracle Hyperion received the highest number of patches, 262. 53 of the 943 (about 6%) security patches provided by the August Critical Patch Update are for non-Oracle CVEs, such as open-source components included in and exploitable within Oracle product distributions. This batch of security patches received 17 updates for Oracle Database products. The following is the product-wise distribution: 6 new security updates for Oracle Database Server with a maximum reported CVSS Base Score of 9.6. None of these updates applies to client-only deployments of the Oracle Database. 7 new security updates for Oracle Autonomous Health Framework with a maximum reported CVSS Base Score of 8.8. 4 new security updates for Oracle Essbase with a maximum reported CVSS Base Score of 9.8. In these security updates, Oracle has covered product families, including Oracle Database Server, Oracle Autonomous Health Framework, Oracle Essbase, Oracle Application Testing Suite, Oracle Commerce, Oracle Communications, Oracle Construction and Engineering, Oracle E-Business Suite, Oracle Enterprise Manager, Oracle Financial Services Applications, Oracle Food and Beverage Applications, Oracle Fusion Middleware, Oracle Analytics, Oracle Hospitality Applications, Oracle Hyperion, Oracle Java SE, Oracle JD Edwards, Oracle MySQL, Oracle PeopleSoft, Oracle Retail Applications, Oracle Siebel CRM, Oracle Supply Chain, Oracle Virtualization. Qualys QID Coverage Qualys has released the following QIDS mentioned in the table: QIDs Title87617Oracle WebLogic Server August 2026 Critical Patch Update (CSPUAUG2026)388372Oracle Managed Virtualization (VM) VirtualBox August 2026 Critical Patch Update (CSPUAUG2026)388371Oracle PeopleSoft Enterprise PeopleTools Product Multiple Vulnerabilities (CSPUAUG2026)388370Oracle Java Standard Edition (SE) August 2026 Critical Patch Update (CSPUAUG2026)20609Oracle Database 19c Critical Patch Update – Aug 2026 Note: The table will be updated with additional QIDs once released. Notable Oracle Vulnerabilities Patched Oracle Fusion Middleware This Critical Patch Update for Oracle Fusion Middleware received 262 security patches. Out of these, 182 vulnerabilities can be exploited over a network without user credentials. A total of 78 CVEs have critical severity ratings. Oracle Hyperion This Critical Patch Update for Oracle Hyperion received 262 security patches. Out of these, 107 vulnerabilities can be exploited over a network without user credentials. A total of 27 CVEs have critical severity ratings. Oracle E-Business Suite This Critical Patch Update for Oracle E-Business Suite received 120 security patches. Out of these, 27 vulnerabilities can be exploited over a network without user credentials. CVE-2026-60782 and CVE-2026-70926 have critical severity ratings with a CVSS score of 9.8. Successful exploitation of these vulnerabilities can lead to remote code execution. Oracle Commerce This Critical Patch Update for Oracle Commerce received 66 security patches. Out of these, 47 vulnerabilities can be exploited over a network without user credentials. A total of 18 CVEs have critical severity ratings. Oracle Siebel CRM This Critical Patch Update for Oracle Siebel CRM received 50 security patches. Out of these, 21 vulnerabilities can be exploited over a network without user credentials. A total of 10 CVEs have critical severity ratings.","https:\u002F\u002Fblog.qualys.com\u002Fvulnerabilities-threat-research\u002F2026\u002F08\u002F19\u002Foracle-critical-patch-update-august-2026-security-update-review","https:\u002F\u002Fik.imagekit.io\u002Fqualys\u002Fwp-content\u002Fthemes\u002Fqualys2020\u002Fimage\u002Fthis-month-in-patches.jpg","2026-08-19T13:49:27+00:00","2026-08-19T14:00:18.274191+00:00",8,[18,21,24,26,28,30],{"name":19,"type":20},"Oracle","vendor",{"name":22,"type":23},"Oracle Fusion Middleware","product",{"name":25,"type":23},"Oracle Hyperion",{"name":27,"type":23},"Oracle Database",{"name":29,"type":23},"Oracle E-Business Suite",{"name":31,"type":23},"Oracle Siebel CRM","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":32,"icon":34,"name":35,"slug":36},null,"Vulnerabilities","vulnerabilities",[38],{"category":39},{"id":32,"icon":34,"name":35,"slug":36},[41,45],{"type":42,"value":43,"context":44},"cve","CVE-2026-60782","Critical severity vulnerability in Oracle E-Business Suite.",{"type":42,"value":46,"context":44},"CVE-2026-70926"]