Skip to content
Oracle April 2026 Critical Patch Update Addresses 481 Vulnerabilities

Oracle April 2026 Critical Patch Update Addresses 481 Vulnerabilities

First seen 21 Apr 2026, 21:43 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 22, 2026 at 19:54 UTC
  • •Oracle's April 2026 CPU includes 481 patches for 241 CVEs across 28 product families.
  • •34 of the patches are classified as critical, with 139 vulnerabilities in Oracle Communications.
  • •Customers are strongly advised to apply the patches to prevent exploitation of known vulnerabilities.

On April 21, 2026, Oracle released its Critical Patch Update (CPU) for April 2026, which includes 481 security patches addressing 241 unique CVEs across 28 product families. Among these, 34 patches are classified as critical. The Oracle Communications product family is notably affected, with 139 vulnerabilities, 93 of which are remotely exploitable without authentication. Other affected systems include Oracle E-Business Suite and Oracle Fusion Middleware, which also have multiple vulnerabilities that can be exploited remotely. Customers are urged to apply these patches immediately to mitigate risks. The update follows ongoing reports of exploitation attempts against previously patched vulnerabilities, emphasizing the importance of timely patch application. This advisory highlights the critical nature of maintaining updated systems to defend against potential attacks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 168d ago How this analysis works

Timeline

2026-03-20
CVE-2026-21992 published
2026-04-21
Oracle released April 2026 Critical Patch Update
2026-04-22
Oracle advises customers to apply patches immediately

More articles in this cluster (12)

Following this threat?

Track Oracle and CVE-2025-15467 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed