[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fuEgLh-HQM4FRkyUoElMK-2SD6B80aHgOwhGROIriD2I":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":41},"98e59878-c840-46bd-824e-7e8adbb6fefb","oracle-releases-245-patches-over-100-remotely-exploitable-without-authentication","f0592772-3854-4299-bf6f-4880f4f3e598","Oracle Releases 245 Patches — Over 100 Remotely Exploitable Without Authentication","Oracle's June 2026 Critical Patch Update highlights a persistent and well-documented risk: organizations that delay applying vendor-issued patches remain exposed to vulnerabilities that are already fixed and publicly known. With over 100 flaws exploitable remotely without authentication, unpatched Oracle environments represent low-effort, high-reward targets for attackers. Oracle explicitly warned that past breaches occurred because customers failed to apply available patches — meaning the threat is not theoretical but actively realized. The concentration of critical flaws in Oracle Fusion Middleware is especially concerning given its widespread enterprise deployment. Timely patch application is not optional hygiene; it is a frontline defense against preventable compromise.","**Immediate actions:**\n- Apply Oracle's June 2026 Critical Patch Update immediately, prioritizing the 120 critical and remotely exploitable vulnerabilities.\n- Audit all Oracle Fusion Middleware deployments to confirm patch status and isolate any unpatched instances from internet-facing networks.\n\n**Long-term improvements:**\n- Establish a formal patch management policy with defined SLAs (e.g., critical patches applied within 72 hours of release).\n- Maintain a continuously updated asset inventory that maps all Oracle product versions to known CVEs.\n- Subscribe to Oracle's Security Alert notifications and integrate them into your vulnerability management workflow.\n\n**Detection measures:**\n- Deploy vulnerability scanning tools configured to detect unpatched Oracle products across all environments on a weekly or continuous basis.\n- Monitor network logs and SIEM alerts for anomalous authentication attempts or exploitation indicators targeting Oracle Middleware endpoints.",[12,13,14,15,16,17,18,19,20],"CIS Control 7: Continuous Vulnerability Management","CIS Control 2: Inventory and Control of Software Assets","NIST SP 800-40 Rev. 4: Guide to Enterprise Patch Management Planning","NIST SI-2: Flaw Remediation","NIST RA-5: Vulnerability Monitoring and Scanning","NIST CM-8: System Component Inventory","ISO\u002FIEC 27001:2022 — A.8.8: Management of Technical Vulnerabilities","ITIL 4: Change Enablement and Problem Management Practices","GDPR Article 32: Security of Processing (appropriate technical measures)","published","2026-06-17T10:20:51.820243+00:00","2026-06-17T10:20:51.703+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fwww.securityweek.com\u002Foracles-second-monthly-security-updates-deliver-245-patches\u002F","oracle-s-second-monthly-security-updates-deliver-245-patches-5e6273","Oracle’s Second Monthly Security Updates Deliver 245 Patches",[29,35],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]