language
Detectat automat

Am preselectat Română și Romanian Leu (lei) pentru tine.

Autentificare
softwarebay.de
softwarebay.de
Oracle Closes Nearly 1000 Security Vulnerabilities in August
News Cybersecurity Oracle Closes Nearly 1000 Security Vulnerabilities...
Cybersecurity

Oracle Closes Nearly 1000 Security Vulnerabilities in August 2026

Oracle Closes Nearly 1000 Security Vulnerabilities in August 2026

Oracle closed a total of 943 security vulnerabilities in its software products in August 2026. This was part of the monthly Critical Security Patch Update (CSPU), which became necessary due to the increasing number of security vulnerabilities. The software manufacturer had previously addressed over 1400 security vulnerabilities in the regular Critical Patch Update (CPU) in July 2026. The majority of the vulnerabilities fixed in August, 262, pertain to Fusion Middleware. Of these, 182 are exploitable over the network without user authentication.

One of these vulnerabilities achieves the maximum CVSS score of 10.0, while 12 additional vulnerabilities have a score of 9.9. Similarly, a comparable number of vulnerabilities were also closed in Hyperion, where 262 vulnerabilities were addressed as well. 107 of these vulnerabilities are exploitable over the network without user authentication, including two with CVSS 10.0 and two with CVSS 9.9. The E-Business Suite, which led the list in July 2026 with 410 security vulnerabilities, recorded 120 vulnerabilities in August. However, this number does not account for vulnerabilities in the components used from Oracle Database and Fusion Middleware.

In the area of database software MySQL, Oracle fixed nine vulnerabilities. Five of these vulnerabilities are exploitable over the network without user authentication, and one achieves a CVSS score of 8.2. The latest available versions of MySQL are 26.7.0, 9.7.2 (LTS), and 8.4.12 (LTS). In Java SE (Standard Edition), a total of five security vulnerabilities were closed, with the highest CVSS score being 7.8. Four of these vulnerabilities are also exploitable over the network without user authentication.

Starting in 2027, Oracle plans to introduce monthly security updates for Java, while maintaining the semi-annual schedule for feature updates. The last security update for the version Java 26, released in March 2026, includes five vulnerabilities. This version will be succeeded by Java 27 in September 2026. Oracle's current security report does not specify whether any of the vulnerabilities have already been exploited in attacks.

The risk assessment is conducted according to the industry standard CVSS 3.1, with a maximum value of 10.0. The security vulnerabilities in Oracle products affect a wide range of companies and organizations worldwide. The necessity of regularly performing security updates is underscored by the increasing number of reported vulnerabilities. Oracle has announced plans to continuously improve security measures to meet user demands.

Tags: Oracle Security Updates Fusion Middleware Hyperion MySQL Java CVSS

💬 Comentarii (0)

Scrie un comentariu

info Va fi publicat dupa moderare
chat_bubble_outline

Inca nu exista comentarii. Fii primul!

Live support available
Lara Maria K.
Lara Maria K.
check_circle Timisoara
Hello! I am Lara Maria. Do you have questions about our products or need help?
chat_bubble