Oracle released a Critical Security Patch Update containing 943 patches for 925 unique CVEs across 23 product families, making it one of the company’s largest recent security releases. The update includes 154 critical patches covering 151 CVEs, with Oracle Fusion Middleware and Oracle Hyperion each receiving 262 patches and Oracle E-Business Suite receiving 120. Oracle said its monthly CSPU program, introduced between quarterly Critical Patch Updates, is intended to accelerate fixes for high-severity flaws.
The most severe issues affect major enterprise platforms including Oracle Internet Directory, Hyperion Data Relationship Management, Hyperion Financial Management, and Oracle WebLogic Server, with some vulnerabilities rated up to CVSS 10.0. Additional critical flaws were reported in Oracle Identity Manager, Siebel CRM Cloud, Helidon, BI Publisher, WebCenter, Oracle Payments, and PeopleSoft PeopleTools. Several of the vulnerabilities are described as unauthenticated network-exploitable and capable of leading to remote code execution or full host compromise, prompting urgent patching recommendations for exposed systems, particularly WebLogic Server and other internet-facing Oracle services.

See real exploitation activity before you spend the cycle.
29 events from the most recent confirmed update back to the earliest known activity.
Oracle published advisory ELSA-2026-57253 for Oracle Linux 8 on August 21, 2026, releasing patches for kernel-related packages including kernel, kernel-core, kernel-devel, kernel-tools, bpftool, perf, and python3-perf. The advisory addressed multiple vulnerabilities including CVE-2024-56602, CVE-2026-46120, CVE-2026-52991, CVE-2026-53189, CVE-2026-63887, CVE-2026-63888, CVE-2026-64048, CVE-2026-64379, and CVE-2026-68388, and the plugin states no known exploits were available.
Oracle published advisory ELSA-2026-55775 for Oracle Linux 8 and 9 on August 20, 2026, releasing patches for java-1.8.0-openjdk and related OpenJDK 8 packages. The advisory addressed CVE-2026-60589, CVE-2026-61308, and CVE-2026-70907, and the Tenable plugin states no known exploits were available.
Oracle Linux 9 patch information for Java 25 OpenJDK packages was published on 2026-08-20, covering multiple java-25-openjdk variants including headless, devel, demo, jmods, src, static-libs, crypto-adapter, and debug builds. The Tenable notice states no known exploits were available.
Oracle published advisory ELSA-2026-500220 for Oracle Linux 9 on August 19, 2026, releasing patches for qemu-kvm, qemu-img, qemu-guest-agent, qemu-kvm-core, qemu-kvm-common, qemu-kvm block components, qemu-kvm-device-usb-host, and qemu-virtiofsd. The advisory addressed multiple vulnerabilities including CVE-2024-6519, CVE-2024-8612, CVE-2026-48002 through CVE-2026-48004, CVE-2026-48914, CVE-2026-5763, CVE-2026-6425, CVE-2026-8343, CVE-2026-8348, and CVE-2026-9238, and the plugin states no known exploits were available.
Oracle published advisory ELSA-2026-57149 for Oracle Linux 9 on August 19, 2026, releasing patches for ansible-core and ansible-test. The advisory addressed CVE-2026-11332, and the Tenable plugin states no known exploits were available.
Oracle published security updates for Oracle WebCenter Sites on 2026-08-19 as part of its August 2026 Critical Security Patch Update. The update addressed 18 vulnerabilities, including CVE-2026-61021 and related CVEs affecting Oracle Fusion Middleware's WebCenter Sites component.
Oracle published advisory ELSA-2026-56521 for Oracle Linux 8 on August 19, 2026, releasing patches for gstreamer1-plugins-bad-free and gstreamer1-plugins-bad-free-devel. The advisory addressed CVE-2026-19387, and the Tenable plugin states no known exploits were available.
On August 18, 2026, Oracle’s August 2026 Critical Security Patch Update addressed multiple Oracle E-Business Suite vulnerabilities affecting supported versions 12.2.3 through 12.2.15. The update included critical takeover flaws in Oracle Payments (CVE-2026-60782), Oracle Workflow (CVE-2026-70926), and Oracle Scripting (CVE-2026-60976).
On August 18, 2026, Oracle published security updates for Oracle VM VirtualBox as part of its August 2026 Critical Security Patch Update cycle. The update addressed multiple vulnerabilities, including CVE-2026-71113 through CVE-2026-71141 and CVE-2026-71151, affecting Oracle VM VirtualBox on Windows, macOS, and Unix systems.
On August 18, 2026, Oracle's Critical Patch Update addressed multiple vulnerabilities affecting Oracle Analytics Server / Oracle Business Intelligence OAS 26.01. The Tenable plugin lists CVEs including CVE-2026-61302, CVE-2026-61305, CVE-2026-71056 through CVE-2026-71059, CVE-2026-71061, CVE-2026-71096 through CVE-2026-71099, CVE-2026-71107, and CVE-2026-71122, and states no known exploits were available.
On August 18, 2026, Oracle published security updates for Oracle Business Intelligence Publisher as part of its August 2026 Critical Security Patch Update. The update addressed multiple vulnerabilities including CVE-2026-61305, CVE-2026-71057, CVE-2026-71058, and CVE-2026-71059, and the Tenable plugin states no known exploits were available.
On August 18, 2026, Oracle released security updates for Oracle Business Intelligence Enterprise Edition (12.2.1.4) as part of its August 2026 Critical Patch Update. The update addressed multiple vulnerabilities including CVE-2026-61305, CVE-2026-71055, CVE-2026-71056, CVE-2026-71057, CVE-2026-71058, CVE-2026-71094, CVE-2026-71095, and CVE-2026-71096, and the Tenable plugin states no known exploits were available.
On 2026-08-18, Oracle released security updates for Oracle WebCenter Portal as part of its August 2026 Critical Security Patch Update cycle. The update addressed multiple vulnerabilities in Oracle Fusion Middleware's WebCenter Portal component, including CVE-2026-60728 through CVE-2026-60733, CVE-2026-61124, CVE-2026-61177, CVE-2026-61193, CVE-2026-61199, CVE-2026-61208, CVE-2026-61212, CVE-2026-61213, CVE-2026-61215, CVE-2026-61219, CVE-2026-61222, CVE-2026-61227, CVE-2026-61228, CVE-2026-61229, CVE-2026-61230, and CVE-2026-70970; the plugin states no known exploits were available.
Oracle published advisory ELSA-2026-55804 for Oracle Linux 8 on August 18, 2026, releasing patches for nghttp2 packages including libnghttp2 and libnghttp2-devel. The advisory addressed CVE-2026-58055, and the Tenable plugin notes exploits were available.
Oracle published advisory ELSA-2026-55603 for Oracle Linux 9 on August 18, 2026, releasing patches for Node.js, npm, V8, and related packages. The advisory addressed multiple vulnerabilities including CVE-2026-11822, CVE-2026-11824, CVE-2026-14257, CVE-2026-54272, CVE-2026-69152, and CVE-2026-69192, and the Tenable plugin notes exploits were available.
On August 18, 2026, Oracle's August 2026 Critical Security Patch Update/Security Patch Update addressed CVE-2026-70906, a denial-of-service vulnerability affecting Oracle JDK and Oracle JRE. Tenable later published a Nessus plugin to detect affected Java installations on Windows, macOS, and Unix systems.
On August 18, 2026, Oracle's August 2026 Critical Patch Update/Security Patch Update addressed multiple Oracle Java SE vulnerabilities affecting Oracle JDK and Oracle JRE, including CVE-2026-60589, CVE-2026-61308, CVE-2026-62574, and CVE-2026-70907. Tenable later published a Nessus plugin to detect affected Java installations on Windows, macOS, and Unix systems.
On 2026-08-18, Amazon Corretto published the corretto-8-2026-Aug-18 advisory stating that Corretto 8 versions prior to 8.504.01.1 were affected by CVE-2026-61308, CVE-2026-60589, and CVE-2026-70907. The recommended remediation was to update to Amazon Corretto Java 8.504.01.1 or later.
Red Hat published fixes for CVE-2026-60315, an Oracle MySQL Server and MySQL Cluster Server: X Plugin vulnerability that can be exploited by an unauthenticated network attacker to cause denial of service and expose a subset of accessible data. The issue was addressed for Red Hat Enterprise Linux 8, 9, and 10 in advisories RHSA-2026:56936, RHSA-2026:56973, and RHSA-2026:56007.
Red Hat published fixes for CVE-2026-60316, an Oracle MySQL Server and MySQL Cluster Server: X Plugin vulnerability that can allow takeover by a high-privileged attacker with network access over multiple protocols. The issue was addressed for Red Hat Enterprise Linux 8, 9, and 10 in advisories RHSA-2026:56936, RHSA-2026:56973, and RHSA-2026:56007.
Red Hat published fixes for CVE-2026-60178, an Oracle MySQL Server and MySQL Cluster Clone Plugin vulnerability that can allow takeover by a high-privileged attacker with network access. The issue was addressed for Red Hat Enterprise Linux 8, 9, and 10 in advisories RHSA-2026:56936, RHSA-2026:56973, and RHSA-2026:56007.
Red Hat published fixes for CVE-2026-60183, an Oracle MySQL Server and MySQL Cluster Clone Plugin vulnerability that can allow takeover by a high-privileged local attacker. The issue was addressed for Red Hat Enterprise Linux 8, 9, and 10 in advisories RHSA-2026:56936, RHSA-2026:56973, and RHSA-2026:56007.
On August 18, 2026, Oracle released security updates for Oracle Essbase as part of its August 2026 Critical Patch Update / Security Patch Update cycle. The update addressed multiple vulnerabilities, including CVE-2026-29167 and numerous related CVEs affecting Oracle Essbase installations on Windows, macOS, and Unix systems.
On August 18, 2026, Oracle published security updates for Oracle Enterprise Manager Cloud Control as part of its August 2026 Critical Security Patch Update. The update addressed multiple vulnerabilities, including CVE-2026-2332 and several additional CVEs referenced by Tenable's detection plugin.
On August 18, 2026, Oracle released its August 2026 Critical Security Patch Update. The release delivered 943 security patches addressing 925 unique CVEs across 23 Oracle product families, including 154 critical patches covering 151 CVEs.
Oracle published advisory ELSA-2026-55446 for Oracle Linux 8 on August 17, 2026, releasing patches for libxfont2 and libxfont2-devel. The advisory addressed CVE-2026-44950 and CVE-2026-59679, and the Tenable plugin states no known exploits were available.
Oracle published advisory ELSA-2026-55440 for Oracle Linux 9 on August 17, 2026, releasing patches for glib2 and related packages. The advisory addressed multiple vulnerabilities including CVE-2026-15588 and CVE-2026-58010 through CVE-2026-58015, and the Tenable plugin notes exploits were available.
Oracle introduced its monthly Critical Security Patch Update cycle in May 2026 to deliver high-severity fixes between its larger quarterly Critical Patch Updates.
Oracle disclosed and patched more than 40 CVEs across more than 10 enterprise product lines in its August 2026 Critical Patch Update advisory, including CVSS 10.0 and 9.9 flaws affecting Oracle Internet Directory, Hyperion products, WebLogic Server, Identity Manager, Siebel CRM Cloud, Helidon, BI Publisher, WebCenter, Oracle Payments, and PeopleSoft PeopleTools. Oracle said patches were available for all affected products and that no active exploitation was known at the time of publication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
43 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcecsirt.bj
Open sourcevirtualbox.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.