Oracle patches 1,449 vulnerabilities in July CPU

July update addresses 1,434 CVEs across 334 products; about 600 flaws allow unauthenticated remote access and many were found using AI.

In its July 2026 Critical Patch Update, Oracle issued 1,449 security fixes addressing 1,434 unique CVEs across 334 products. The fixes cover database, middleware, enterprise applications, virtualization and industry suites, naming Database Server, APEX, GoldenGate, NoSQL Database, Java SE and MySQL among affected components. Hundreds of the patched vulnerabilities received a critical severity rating.

The largest counts of patches were in E-Business Suite (410), Fusion Middleware (355), Communications (168) and PeopleSoft (84). Roughly 600 of the fixes address vulnerabilities that can be exploited remotely without authentication. Oracle credited external researchers for only a few dozen findings and reported that most discoveries came from internal processes.

Oracle disclosed it uses advanced AI systems, including Anthropic’s Claude Mythos and OpenAI’s top models, to speed vulnerability discovery and remediation. The company applies AI-driven analysis across its software, Oracle Health products and the open-source components it develops and relies on. The July update follows recent incidents in which attackers exploited a PeopleSoft zero-day and an E-Business Suite flaw.

Security teams should consult Oracle’s patch documentation for details on affected versions and mitigation steps, and schedule testing and deployment according to their change-management procedures.

Articles by this author