Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates
Oracle released a massive quarterly security update addressing over 1,400 vulnerabilities, primarily identified through the use of AI. The update includes fixes for a wide range of products and services, highlighting the increasing reliance on artificial intelligence for vulnerability detection and patching. Organizations are urged to apply these patches promptly to mitigate the risk of exploitation by threat actors.
Oracle has released its July 2026 Critical Patch Update (CPU), containing more than 1,400 security patches. The update addresses 1,434 unique CVEs across 334 products, encompassing a diverse range of software and services. Affected products include Database Server, APEX, Autonomous Health Framework, Essbase, Global Lifecycle Management, GoldenGate, NoSQL Database, Spatial Studio, SQL Developer, TimesTen In-Memory Database, Application Testing Suite, Commerce, Communications, Construction and Engineering, and E-Business Suite.
Many of the vulnerabilities addressed are remotely exploitable, requiring no authentication to trigger an attack. The highest numbers of vulnerabilities were found in E-Business Suite (410), Fusion Middleware (355), Communications (168), and PeopleSoft (84).
Oracle indicated that a significant portion of these newly patched flaws were discovered internally, leveraging advanced AI systems, including Anthropic’s Claude Mythos and OpenAI’s most capable models, to accelerate and refine vulnerability detection and patching processes. This AI-driven approach is being applied to Oracle’s own software and services, as well as open-source components.
Organizations are strongly advised to install these patches immediately, as threat actors frequently exploit Oracle product vulnerabilities in their attacks, such as the exploitation of a PeopleSoft zero-day and a recently patched EBS vulnerability. The company cited the potential for attacks leveraging these known weaknesses.