Tenable Oracle April 2026 Critical Patch Update Addresses 481 Vulnerabilities
Article Content
- •Oracle's April 2026 CPU includes 481 patches for 241 CVEs across 28 product families.
- •34 of the patches are classified as critical, with 139 vulnerabilities in Oracle Communications.
- •Customers are strongly advised to apply the patches to prevent exploitation of known vulnerabilities.
On April 21, 2026, Oracle released its Critical Patch Update (CPU) for April 2026, which includes 481 security patches addressing 241 unique CVEs across 28 product families. Among these, 34 patches are classified as critical. The Oracle Communications product family is notably affected, with 139 vulnerabilities, 93 of which are remotely exploitable without authentication. Other affected systems include Oracle E-Business Suite and Oracle Fusion Middleware, which also have multiple vulnerabilities that can be exploited remotely. Customers are urged to apply these patches immediately to mitigate risks. The update follows ongoing reports of exploitation attempts against previously patched vulnerabilities, emphasizing the importance of timely patch application. This advisory highlights the critical nature of maintaining updated systems to defend against potential attacks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (12)
Following this threat?
Track Oracle and CVE-2025-15467 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…