Skip to content
Oracle May 2026 Critical Security Patch Update Addresses 35 CVEs

Oracle May 2026 Critical Security Patch Update Addresses 35 CVEs

Tenable Research Special Operations May 28, 2026

Oracle addresses 35 CVEs in its May 2026 Critical Security Patch Update with 35 patches, including 11 critical updates.

On May 28, Oracle released its Critical Security Patch Update (CSPU) for May 2026 . Beginning in May 2026, Oracle introduced CSPUs as a monthly release cycle that sits between the larger quarterly Critical Patch Updates (CPUs), addressing a focused set of high-severity issues on a faster cadence. This CSPU contains fixes for 35 unique CVEs in 35 security updates across 5 Oracle product families. Out of the 35 security updates published, 31.4% of patches were assigned a critical severity. High severity patches accounted for the bulk of security patches at 51.4%, followed by critical severity patches at 31.4%.

This month's update includes 11 critical patches across 11 CVEs.

This month's update saw the Oracle E-Business Suite product family contain the highest number of patches at 12, accounting for 34.3% of the total patches, followed by Oracle REST Data Services at 11 patches, which accounted for 31.4% of the total patches.

A full breakdown of the patches for this CSPU can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication.

Customers are advised to apply all relevant patches in this CSPU. Please refer to the May 2026 advisory for full details.

A list of Tenable plugins to identify these vulnerabilities will appear here as they're released. This link uses a filter to ensure that all matching plugin coverage will appear as it is released.

Join Tenable's Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.

Extracted Entities