Oracle Critical Patch Updates
oracle-cpu · A · active
https://www.oracle.com/security-alerts/
Oracle quarterly Critical Patch Updates and individual Security Alerts (added 2026-05-08). Quarterly cadence (Jan / Apr / Jul / Oct); also publishes off-cycle Security Alerts for ITW-exploited bugs. 2026-05-08 audit: WebFetch surfaced CPU Apr 2026 + CVE-2026-21992 Mar 20 alert. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → bridge: python3 tools/fetch_source.py url https://www.oracle.com/security-alerts/ (listing) then bridge: python3 tools/fetch_source.py url https://www.oracle.com/security-alerts/<cpu-or-alert>.html for the advisory body. AVOID: WebFetch 403s oracle.com, skip WebFetch, go straight to the bridge. Quarterly CPU cadence (Jan/Apr/Jul/Oct) plus off-cycle Security Alerts; don't expect daily change.. | 2026-07-05 admiralty audit: A (HIGH->A) status active->active, first-party Oracle PSIRT, own-product advisories; bridge listing live/drillable. Justified A: vendor PSIRT for its own products. Quarterly cadence; Jul 2026 CPU due mid-month. | 2026-09-20 quality audit: the recorded cadence was WRONG and caused a miss. Oracle runs TWO release lines: the quarterly cumulative Critical Patch Update (CPU, third Tuesday of Jan/Apr/Jul/Oct) AND, since May 2026, a Critical Security Patch Update (CSPU) on the third Tuesday of Feb/Mar/May/Jun/Aug/Sep/Nov/Dec. That is EIGHT further release dates a year. URL pattern: https://www.oracle.com/security-alerts/cspu<mon><year>.html (e.g. cspusep2026.html), alongside cpu<mon><year>.html. The earlier note said 'Quarterly cadence ... don't expect daily change', and the September 2026 CSPU (2026-09-15, six unauthenticated CVSS 10.0 flaws) passed six consecutive fires unremarked although the store had already published the June and August CSPUs. FETCH -> bridge: python3 tools/fetch_source.py extract https://www.oracle.com/security-alerts/cspu<mon><year>.html returns the full risk matrix. Check this source in the week after every third Tuesday, not only in Jan/Apr/Jul/Oct.
Cited in 9 entries
Citation cadence
Citation days per ISO week (16 weeks of coverage span, total 8).
- Oracle's September 2026 Critical Security Patch Update carries six unauthenticated CVSS 10.0 flaws across WebLogic Server, Access Manager, Forms, Internet Directory, Platform Security for Java and Hyperion Financial Management2026-09-20
- Oracle's August 2026 Critical Security Patch Update carries three unauthenticated CVSS 10.0 flaws, one of them in the LDAP server of Oracle Internet Directory2026-08-20
- Oracle July 2026 CPU, nine unauthenticated CVSS 10.0 flaws in Fusion Middleware, with NCSC-NL assessing large-scale abuse as very likely in the short term2026-07-26
- CVE-2026-46817, Oracle E-Business Suite (Payments): unauthenticated RCE now CISA KEV-listed after quiet in-the-wild exploitation (CVSS 9.8)2026-07-16
- CVE-2026-46978 / CVE-2026-35278, Oracle June 2026 CSPU: unauthenticated Solaris RAD flaw (CVSS 10.0) and PeopleSoft RCE (9.8)2026-06-18
- BSI flags 13 vulnerabilities patched in Zammad 7.1, admin privilege escalation in a DACH public-sector helpdesk platform2026-06-18
- CVE-2026-25089, Fortinet FortiSandbox: unauthenticated OS command injection in the web UI's VNC-launch handler (CVSS 9.8)2026-06-12
- ShinyHunters Oracle PeopleSoft campaign: gadget-chain access, SSH default-credential lateral movement, mass exfiltration2026-06-11
- CVE-2024-21182, Oracle WebLogic Server: unauthenticated T3/IIOP data access, KEV-listed on active exploitation2026-06-03