Get Your Free Report
Start for Free
SOCRadar® Cyber Intelligence Inc. | Oracle July 2026 CPU: 1,449 Patches, 10 Score Max
Jul 23, 2026
6 Mins Read
Moon

Oracle July 2026 CPU: 1,449 Patches, 10 Score Max

Oracle July 2026 Critical Patch Update ships 1,449 patches covering 1,434 CVEs across 334 products in 32 product families, making it the largest quarterly release Oracle has put out. Hundreds of those patches carry critical severity ratings, and roughly 600 close vulnerabilities that attackers could exploit remotely without valid credentials.

Here is a closer look at the vulnerabilities worth prioritizing first.

What Are the CVSS 10.0 Flaws in Oracle July 2026 Updates?

Fusion Middleware carries the heaviest concentration of high-risk flaws in the entire release. Of its 355 new vulnerabilities, 219 are remotely exploitable without authentication, and ten of those landed at a perfect 10.0, covering nine unique CVE identifiers since one affects two related products.

Each share the same vectors: reachable over the network with low attack complexity, no privileges or user interaction required, and full compromise of confidentiality and integrity, plus availability in all but two cases.

  • CVE-2026-60358 (CVSS 10.0) – Oracle Access Manager Authentication Engine Vulnerability
  • CVE-2026-60217 (CVSS 10.0) – Oracle Coherence Core Vulnerability
  • CVE-2026-47056 (CVSS 10.0) – Oracle Data Integrator REST Service Vulnerability
  • CVE-2026-60365 (CVSS 10.0) – Oracle HTTP Server & WebLogic Server Proxy Plug-in Vulnerability
  • CVE-2026-60366 (CVSS 10.0) – Oracle Platform Security for Java Centralized Third-Party Jars Vulnerability
  • CVE-2026-60360 (CVSS 10.0) – Oracle Unified Directory OUD Core Vulnerability
  • CVE-2026-60644 (CVSS 10.0) – Oracle WebCenter Content Web Content Management Vulnerability
  • CVE-2026-60389 (CVSS 10.0) – Service Delivery Platform Messaging Enabler Vulnerability
  • CVE-2026-60379 (CVSS 10.0) – Service Delivery Platform Messaging Enabler Vulnerability

Details of CVE-2026-60365 (SOCRadar Vulnerability Intelligence)

Details of CVE-2026-60365 (SOCRadar Vulnerability Intelligence)

Because each of these sits in a shared or gateway role, from identity and directory services to the web tier fronting other applications, a single compromised instance can expose whatever depends on it.

CVE-2026-61211 (CVSS 9.9) – Oracle Database RDBMS DBMS_CLOUD Package Vulnerability

Following the group of perfect scores, a critical 9.9 database flaw stands as the next most urgent priority.

CVE-2026-61211 lets a low-privileged attacker with Execute DBMS_CLOUD privilege and network access over Oracle Net take over the database, with the potential to affect additional products beyond RDBMS itself. It affects Database Server versions 19.3 through 19.31 and 23.4.0 through 23.26.2.

Details of CVE-2026-61211 (SOCRadar Vulnerability Intelligence)

Details of CVE-2026-61211 (SOCRadar Vulnerability Intelligence)

Other Notable Critical Fixes in the Oracle July 2026 CPU

A few more flaws in this release deserve a second look before the rest of the queue.

  • CVE-2026-47040 (CVSS 9.1) – Oracle Net Services Connection Manager Vulnerability. Remotely exploitable without authentication.
  • CVE-2026-2332 (CVSS 9.1) – Oracle GoldenGate Big Data and Application Adapters Vulnerability, tied to Eclipse Jetty and exploitable without authentication.
  • CVE-2026-7383 (CVSS 8.1) – OpenSSL TLS Vulnerability affecting Database Server and Autonomous Health Framework. The same patch resolves 19 bundled OpenSSL CVEs.

Details of CVE-2026-47040 (SOCRadar Vulnerability Intelligence)

Details of CVE-2026-47040 (SOCRadar Vulnerability Intelligence)

Oracle’s TimesTen In-Memory Database also picked up two fixes rated critical severity in this release. Oracle’s summary does not break out individual CVE numbers or scores for either one.

Which Products Got the Most Oracle July 2026 Patches?

Four product lines account for the bulk of this release. Oracle E-Business Suite received fixes for 410 vulnerabilities, the largest share in the update. Fusion Middleware followed with 355, Communications with 168, and PeopleSoft with 84, together making up more than 1,000 of the 1,449 total patches.

What Is Driving the Oracle July 2026 Patch Count?

The patch count has grown quickly over Oracle’s last several quarterly releases, and this one is by far the largest yet. Oracle has said artificial intelligence is playing a growing role in finding these flaws internally, with only a small number credited to external researchers and the rest found in house using AI-assisted analysis, including systems from Anthropic and OpenAI.

This is also the first quarterly release since Oracle introduced a separate monthly Critical Security Patch Update program in May 2026, adding a second, overlapping patch cadence.

This growth is not unique to Oracle. Vendors are turning to AI to speed up vulnerability discovery, and that shift is already reshaping how large security releases have become. Microsoft has described a similar move with its own AI-assisted discovery system, featuring MDASH, which coordinates more than 100 specialized AI agents to find and validate flaws across its codebase. That approach played out in Microsoft’s July 2026 Patch Tuesday, which addressed 622 CVEs, one of the largest single releases on record. Oracle’s own numbers point to the same pattern.

Responding to the Oracle July 2026 CPU With SOCRadar XTI

With 1,449 patches across 334 products, patching everything at once is unrealistic. Triage in stages: fix the unauthenticated, remotely exploitable flaws on internet-facing systems first, then trusted internal systems, then the rest based on actual exposure. E-Business Suite needs extra care too, since some of its risk comes from underlying Database and Fusion Middleware versions that sit outside its own product matrix.

Oracle’s full July 2026 Critical Patch Update advisory has the complete list of products, versions, and CVEs. Reviewing a release this size gets harder without visibility into what an organization is actually running and exposed to. SOCRadar XTI supports that work through modules including:

  • Cyber Threat Intelligence (CTI): Tracks CVEs like these as the vendors publish them, complete with CVSS scoring, exploit alerts, and affected technologies. It also follows threat actor activity and behavioral patterns tied to specific vulnerabilities, and surfaces early signals of active or in-development exploitation, including proof-of-concept code and Dark Web chatter.
  • Attack Surface Management (ASM): Maps your organization’s external digital footprint, including cloud infrastructure, SaaS applications, internet-facing systems, identities, and third-party integrations. Applied to a release like this, it identifies which of your assets are actually running the affected Oracle products and versions, then ranks them by exposure so the highest-risk systems surface first.

SOCRadar’s Vulnerability Intelligence

SOCRadar’s Vulnerability Intelligence

Used together, CTI and ASM compress a thousand-patch release into a shorter, exposure-ranked action list.