Skip to content
Rush Commerce
Field Notes3 min read

Oracle's July CPU: 1,235 CVEs hit your back office

Oracle's July 2026 Critical Patch Update fixes 1,235 CVEs across 32 product families. E-Business Suite took 410 patches. Here's how to triage it.

Oracle shipped its quarterly Critical Patch Update today, and the number is absurd: 1,235 unique CVEs delivered in 1,449 security updates across 32 product families. If you run E-Business Suite, PeopleSoft, Fusion Middleware, or MySQL — or you pay a vendor who does — this is your next two weeks. The Oracle July 2026 CPU is not a routine drop you schedule for next quarter.

What actually happened

Per Tenable's breakdown of the July 2026 advisory, the patch counts land like this:

  • E-Business Suite — 410 patches, 28% of the entire release. 45 are remotely exploitable with no authentication.
  • Fusion Middleware — 355 patches, and 219 of them are remotely exploitable without credentials. That's the scariest column in the table.
  • Communications — 168 patches, 122 remote-no-auth.
  • PeopleSoft — 84 patches, 45 remote-no-auth.
  • MySQL — 54 patches, 9 remote-no-auth.

Severity splits out to 261 critical patches across 228 CVEs, with high-severity issues making up roughly 53% of the release. Oracle's guidance is the usual: apply everything relevant this quarter.

It wasn't an isolated bad day either. Microsoft's July Patch Tuesday shipped over 600 CVEs including three zero-days, two under active exploitation. Two vendors, one month, four figures of vulnerabilities.

Why this patch update matters for your business

You are not going to test 410 EBS patches. Nobody is. So the job isn't "patch everything" — it's ranking, and the ranking column that matters is remotely exploitable without authentication. That means an attacker needs network reach and nothing else. No stolen password, no phishing, no insider. A scan finds you, and the exploit works.

So the triage order is mechanical. First: anything in this CPU that's remote-no-auth and reachable from the internet. Second: remote-no-auth on your internal network. Everything else goes in the normal cycle.

Which means the real prerequisite isn't patching at all — it's knowing what you're running and what can reach it. We've watched this exact CPU cycle burn companies who discovered a Fusion Middleware instance nobody remembered standing up. We wrote about CVE-2026-46817 two weeks ago: the fix existed for six weeks before attackers got there, and plenty of businesses still lost the race. Patch latency is the vulnerability.

Key takeaways

  • Oracle's July 2026 CPU fixes 1,235 CVEs in 1,449 patches across 32 product families — released July 21
  • E-Business Suite got 410 patches; Fusion Middleware got 355, of which 219 are remotely exploitable with no authentication
  • Triage by "remote, no auth, internet-reachable" first — you cannot regression-test 400 patches and shouldn't try
  • The blocker is almost never the patch. It's not having an inventory of what you run and what can reach it

Can you name every Oracle instance on your network right now? We inventory what you're actually running, rank exposure by what an unauthenticated attacker can reach, and set a patch cadence that survives a 1,200-CVE quarter. See how we harden the boring stuff or get an exposure check this week.

Sources: Tenable, Oracle, Malwarebytes.

  • #oracle
  • #patch-management
  • #cve
  • #erp
  • #security
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.