Blogs.Oracle
Oracle August 2026 CSPU Addresses 925 CVEs with 154 Critical Patches
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On August 18, 2026, Oracle released its Critical Security Patch Update (CSPU) addressing 925 unique CVEs with 943 patches, including 154 classified as critical. This update marks a significant increase in patch volume compared to previous updates, with a nearly fourfold rise from June 2026's CSPU. The CSPU covers 23 product families, including Oracle Fusion Middleware and Oracle Hyperion, which each received 262 patches. The severity breakdown indicates that 16.3% of patches are critical, while high severity patches account for 59%. This update is part of Oracle's new monthly CSPU cycle introduced in May 2026, aimed at addressing high-severity vulnerabilities more quickly. Affected systems span a wide range of Oracle products, emphasizing the extensive scope of this update. Administrators are urged to apply these patches promptly to mitigate potential risks.
Key Points: • Oracle's August 2026 CSPU includes 943 patches for 925 CVEs, with 154 critical updates. • The update covers 23 product families, significantly expanding the scope from previous releases. • Administrators are advised to apply these patches quickly due to the high volume of critical vulnerabilities.