Oracle released its third quarterly edition of this year’s Critical Patch Update. The update received patches for 1449 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle E-Business Suite received the highest number of patches, 410, constituting about 28% of the total patches released.
1235 of the 1449 (about 86%) security patches in the July Critical Patch Update are for non-Oracle CVEs, such as open-source components included in, and exploitable within, Oracle product distributions.
This batch of security patches received 72 updates for Oracle Database products. The following is the product-wise distribution:
- 15 new security updates for Oracle Database Server with a maximum reported CVSS Base Score of 9.9.
- Three of these updates apply to client-only deployments of the Oracle Database.
- Three new security updates for Oracle APEX with a maximum reported CVSS Base Score of 5.5.
- Four new security updates for the Oracle Autonomous Health Framework with a maximum reported CVSS Base Score of 8.1.
- One new security update for Oracle Essbase with a reported CVSS Base Score of 4.8.
- One new security update for Oracle Global Lifecycle Management with a reported CVSS Base Score of 8.1.
- 27 new security updates for Oracle GoldenGate with a maximum reported CVSS Base Score of 9.1.
- No new security updates for Oracle Graph Server and Client, but third-party patches are provided.
- One new security update for Oracle NoSQL Database.
- One new security update for Oracle Spatial Studio.
- Five new security updates for Oracle SQL Developer, all remotely exploitable without authentication (max CVSS not yet verified).
- 14 new security updates for Oracle TimesTen In-Memory Database, four of which are remotely exploitable without authentication.
In these security updates, Oracle has covered product families, including Oracle E-Business Suite, Oracle Fusion Middleware, Oracle Communications, Oracle PeopleSoft, Oracle Database Products, Oracle MySQL, Oracle Siebel CRM, Oracle Commerce, Oracle Supply Chain, Oracle Financial Services Applications, Oracle Analytics, Oracle Application Testing Suite, Oracle Construction and Engineering (Primavera), Oracle Enterprise Manager, Oracle Food and Beverage Applications (Hospitality Simphony), Oracle Health Sciences / HealthCare Applications, Oracle Hospitality (Cruise SPMS), Oracle Java SE, Oracle JD Edwards, Oracle Retail Applications, Oracle Systems (Solaris), and Oracle Virtualization (VM VirtualBox)
Qualys QID Coverage
Qualys has released the following QIDS mentioned in the table:
| QIDs | Title |
| 388003 | Oracle JDeveloper Security Update (CPUJUL2026) |
| 387986 | Oracle Java Standard Edition (SE) July 2026 Critical Patch Update (CPUJUL2026) |
| 387988 | Oracle Coherence July 2026 Critical Patch Update (CPUJUL2026) |
| 387996 | Oracle Managed Virtualization (VM) VirtualBox July 2026 Critical Patch Update (CPUJUL2026) |
| 387984 | Oracle Hypertext Transfer Protocol (HTTP) Server July 2026 Critical Patch Update (CPUJUL2026) |
| 296138 | Oracle Solaris 11.4 Support Repository Update (SRU) 94.221.2 Missing (CPUJUL2026) |
| 87614 | Oracle WebLogic Server July 2026 Critical Patch Update (CPUJUL2026) |
| 20599 | Oracle E-Business Suite Security Update (CPUJUL2026) |
| 20600 | Oracle MySQL Server July 2026 Critical Patch Update (CPUJULY2026) |
| 20601 | Oracle E-Business Suite Security Update (CPUJUL2026) |
Note: The table will be updated with additional QIDs once released.