Morningstar Azul and Oracle Announce Monthly Security Updates for Java
Article Content
- •Azul and Oracle will deliver monthly Critical Security Patch Updates for Java starting August 2026.
- •The shift to monthly updates is in response to the rapid discovery and exploitation of vulnerabilities by AI.
- •Organizations must adapt their patching processes to accommodate the increased frequency of updates.
Azul and Oracle are transitioning to a monthly cadence for Critical Security Patch Updates (CSPUs) for Java, starting in August 2026. This change is driven by the increasing speed at which AI identifies and exploits vulnerabilities, making the traditional quarterly updates insufficient. Azul will provide CSPUs for all supported Long-Term Support (LTS) versions, including Java 8, 11, 17, 21, 25, and the current release Java 26. Oracle also plans to implement a similar monthly update schedule, with the first CSPU set for August 18, 2026. Both companies emphasize a focus on security and stability, avoiding new features in these updates. This shift aims to mitigate the risks associated with waiting for quarterly updates, which can leave systems vulnerable for extended periods. Organizations using Java are advised to prepare for more frequent patching to maintain security compliance.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…