Oracle Releases 943 Patches in August 2026 Security Update

www.news4hackers.com-oracle-releases-943-patches-in-august-2026-security-update-oracle-releases-943-patches-in-august-2026-security-update

Oracle released 943 security patches in the August 2026 CSPU, addressing over 1,000 vulnerabilities across 24 products.

Overview of the August 2026 CSPU

Oracle disclosed on Tuesday the release of 943 security patches as part of the August 2026 Critical Security Patch Update (CSPU), marking the third monthly security release of the year. The update addresses over 1,000 distinct vulnerabilities across 24 products, with more than 460 flaws capable of remote exploitation without authentication. The patches resolve a range of security issues, including 150 critical-severity vulnerabilities and nearly 90 flaws rated with a CVSS score of 9.8 or higher.

Key Products and Vulnerabilities

Fusion Middleware and Hyperion received the highest number of patches in this release, each containing 262 updates. Fusion Middleware addressed 182 remotely exploitable vulnerabilities, while Hyperion resolved 107 such issues. Additional significant updates were issued for E-Business Suite (120 patches), Commerce (66), Siebel CRM (50), and Supply Chain (46). Other affected products include VM VirtualBox, Analytics, PeopleSoft, Communications, Enterprise Manager, MySQL, Financial Services Applications, Autonomous Health Framework, Application Testing Suite, JD Edwards, Database Server, Java SE, Retail Applications, Essbase, Food and Beverage Applications, Construction and Engineering, and Hospitality Applications.

Comparison with Previous Updates

The August 2026 CSPU addresses slightly fewer vulnerabilities compared to the July 2026 update, which resolved 1,449 issues across over 1,400 unique CVEs.

Customer Recommendations and Industry Context

Oracle attributed the high volume of patches to advancements in AI-driven vulnerability discovery. The company previously announced the use of advanced large language models (LLMs) to accelerate patch development. Customers are urged to deploy the updates promptly, as malicious actors have targeted unpatched Oracle systems. Oracle’s advisory noted ongoing attempts to exploit vulnerabilities for which patches have already been released. The release highlights the continued challenge of managing complex software ecosystems amid evolving threat landscapes. The update follows a series of recent security disclosures, including vulnerabilities in WordPress plugins, macOS screen sharing features, GeoServer, and VMware vCenter. Additional patches were issued for webkit components in macOS and iOS, while multiple data breaches affecting millions of users were reported globally. Oracle’s August 2026 CSPU underscores the importance of proactive vulnerability management, particularly as threat actors increasingly leverage automated tools to identify and exploit weaknesses in enterprise software. The release also reflects broader industry trends, including the integration of AI technologies in both threat detection and defensive measures.



About Author

en_USEnglish