Oracle issues 943 patches in August 2026 security update

Oracle released 943 patches in its August 2026 Critical Security Patch Update, fixing more than 1,000 CVEs across two dozen products and over 460 remotely exploitable flaws.
Oracle on Tuesday released 943 security patches as part of its August 2026 Critical Security Patch Update (CSPU). The advisory says the fixes cover more than 1,000 unique CVEs across about two dozen products and address over 460 vulnerabilities that attackers can exploit remotely without authentication. The advisory lists more than 150 critical-severity defects, with nearly 90 scored 9.8 or higher on the CVSS scale.
Fusion Middleware and Hyperion received the largest share of patches, 262 each. According to the advisory, the Fusion Middleware update closes 182 remotely exploitable bugs and includes 80 critical-severity flaws. The Hyperion refresh resolves 107 remotely exploitable weaknesses and contains 27 critical-severity flaws. Oracle also released patches for E-Business Suite (120), Commerce (66), Siebel CRM (50) and Supply Chain (46). Additional fixes address VM VirtualBox, Analytics, PeopleSoft, Communications, Enterprise Manager, MySQL, Financial Services Applications, Autonomous Health Framework, Application Testing Suite, JD Edwards, Database Server, Java SE, Retail Applications, Essbase, Food and Beverage Applications, Construction and Engineering, and Hospitality Applications.
The August bundle is smaller than Oracle’s July 2026 Critical Patch Update, which contained 1,449 patches that addressed more than 1,400 CVEs. Oracle has said it is using advanced large language models to speed vulnerability discovery and patch development, a practice the company links to a higher volume of identified flaws.
The advisory warns customers to apply updates promptly, noting that attackers sometimes exploit vulnerabilities after patches are released. The company wrote, “Oracle continues to periodically receive reports of attempts to maliciously exploit vulnerabilities for which Oracle has already released security patches.”
Administrators are urged to review the detailed advisories for affected components, prioritize fixes with the highest CVSS scores and remote-exploitability, and follow standard testing and deployment procedures before rolling updates into production.







