Back beyondmachines.net Oracle Issues Record-Breaking July 2026 Security Update with 1,449 Patches BeyondMachines / 4h This release, issued on July 21, 2026, delivers 1,449 new security patches across dozens of product families, patching vulnerabilities in both Oracle's own code and the third-party components bundled within its products. A large concentration of critical flaws affects Oracle Fusion Middleware, which alone received 355 patches, 219 of them remotely exploitable without credentials.
Oracle has published its July 2026 Critical Patch Update, a cumulative collection of security patches spanning its entire product portfolio.
This release , issued on July 21, 2026, delivers 1,449 new security patches across dozens of product families, patching vulnerabilities in both Oracle's own code and the third-party components bundled within its products.
A large concentration of critical flaws affects Oracle Fusion Middleware, which alone received 355 patches, 219 of them remotely exploitable without credentials. Other high-impact product families in this cycle include Oracle E-Business Suite (410 patches), Oracle Communications (168 patches), Oracle PeopleSoft (84 patches), Oracle Database Server, and Oracle MySQL.
Critical vulnerabilities summary
A substantial portion of this update addresses widely used third-party libraries embedded across many products. Recurring components include Apache Log4j (CVE-2026-34481), Apache Kafka (CVE-2026-33557), Netty (CVE-2026-42587), Spring Framework (CVE-2026-41855), Lodash (CVE-2026-4800), and Perl (CVE-2026-4176), among others.
Oracle strongly urges customers to apply these patches without delay, noting that it continues to receive reports of attackers successfully compromising systems where organizations failed to apply previously released fixes. Because many of these flaws are remotely exploitable without authentication, unpatched deployments exposed to the internet present a significant risk of data theft, system compromise, and service disruption.
For customers unable to apply the patches immediately, Oracle recommends interim risk-reduction measures such as blocking the network protocols required by an attack, or removing privileges and package access from users who do not require them. However, Oracle notes that these workarounds may break application functionality and should not be treated as long-term solutions.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
