Oracle Critical Patch Updates
oracle-cpu · A · active
https://www.oracle.com/security-alerts/
Oracle quarterly Critical Patch Updates and individual Security Alerts (added 2026-05-08). Quarterly cadence (Jan / Apr / Jul / Oct); also publishes off-cycle Security Alerts for ITW-exploited bugs. 2026-05-08 audit: WebFetch surfaced CPU Apr 2026 + CVE-2026-21992 Mar 20 alert. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → bridge: python3 tools/fetch_source.py url https://www.oracle.com/security-alerts/ (listing) then bridge: python3 tools/fetch_source.py url https://www.oracle.com/security-alerts/<cpu-or-alert>.html for the advisory body. AVOID: WebFetch 403s oracle.com — skip WebFetch, go straight to the bridge. Quarterly CPU cadence (Jan/Apr/Jul/Oct) plus off-cycle Security Alerts; don't expect daily change.. | 2026-07-05 admiralty audit: A (HIGH->A) status active->active — first-party Oracle PSIRT, own-product advisories; bridge listing live/drillable. Justified A: vendor PSIRT for its own products. Quarterly cadence; Jul 2026 CPU due mid-month.
Cited in 9 entries
Citation cadence
Citation days per ISO week (7 weeks of coverage span, total 7).
- CVE-2026-46817 — Oracle E-Business Suite (Payments): unauthenticated RCE now CISA KEV-listed after quiet in-the-wild exploitation (CVSS 9.8)2026-07-16
- CVE-2026-46978 / CVE-2026-35278 — Oracle June 2026 CSPU: unauthenticated Solaris RAD flaw (10.0) and PeopleSoft RCE (9.8)2026-06-22
- CVE-2026-46978 / CVE-2026-35278 — Oracle June 2026 CSPU: unauthenticated Solaris RAD flaw (CVSS 10.0) and PeopleSoft RCE (9.8)2026-06-18
- BSI flags 13 vulnerabilities patched in Zammad 7.1 — admin privilege escalation in a DACH public-sector helpdesk platform2026-06-18
- CVE-2026-35273 — Oracle PeopleSoft: confirmed zero-day exploited by ShinyHunters (UNC6240), education sector hit hardest2026-06-14
- Oracle PeopleSoft CVE-2026-35273 attributed to ShinyHunters; confirmed zero-day, 100+ victims, education sector hit hardest2026-06-13
- ShinyHunters PeopleSoft campaign — Oracle confirms CVE-2026-35273 and ships an out-of-band patch; Nottingham quantifies 455,000 records2026-06-12
- CVE-2026-25089 — Fortinet FortiSandbox: unauthenticated OS command injection in the web UI's VNC-launch handler (CVSS 9.8)2026-06-12
- CVE-2024-21182 — Oracle WebLogic Server: unauthenticated T3/IIOP data access, KEV-listed on active exploitation2026-06-03