With 925 security flaws, Oracle fixed noticeably fewer software bugs in August than in July's 1,449. Even so, numerous critical vulnerabilities are among them that urgently need attention, since some are considered easily exploitable.
An extra format for critical flaws
Oracle normally patches its software on four patch days a year, scheduled for January, April, July, and October in 2026. To close critical security flaws faster, the vendor additionally introduced the Critical Security Patch Update (CSPU), with the first one released on May 28, 2026. CSPUs have since been published every third Tuesday of the month. The August CSPU brought updates for 925 vulnerabilities, hitting the products Hyperion, E-Business Suite, and Fusion Middleware especially hard.
Hyperion and Fusion Middleware at CVSS 10.0
Oracle Hyperion Data Relationship Management and Hyperion Financial Management both carry the maximum CVSS score of 10.0 with vulnerabilities CVE-2026-70880 and CVE-2026-70921. Hyperion is a suite for enterprise planning, budgeting, consolidation, and financial reporting; a total of 261 of the flaws closed in August belong to the suite, affecting versions 11.2.23.0.000 and 11.2.25.0.000.
Even more flaws affect Fusion Middleware, which was vulnerable to cyberattacks through 262 vulnerabilities. The one rated most dangerous, CVE-2026-61241, also carries CVSS 10.0 and sits in the OID LDAP Server component of the Internet Directory directory service, part of Fusion Middleware. Various other products within the suite carry additional critical flaws, affecting versions including 12.2.1.19.0, 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 14.1.2.1.0, 8.5.8, 15.1.1.0.0, 4.5.33.2.19, 4.5.13.2.20, 1.4.19, 1.4.20, and 4.5.03.2.18.
E-Business Suite at risk from 120 flaws
Oracle's E-Business Suite contains a total of 120 vulnerabilities, two of them critical. CVE-2026-60782 (CVSS score 9.8) affects Oracle Payment, and CVE-2026-70926 (CVSS score 9.8) affects Oracle Workflow, both affecting E-Business Suite versions 12.2.3 through 12.2.15. Neither Oracle's overview nor ENISA's database provides specific details on these vulnerabilities, describing them only as easily exploitable. Successful attacks require network access, and no prior authentication is necessary.
The remaining security flaws Oracle closed in the August CSPU affect products or product families including Database Server, Autonomous Health Framework, Application Testing Suite, Commerce, Communications, Enterprise Manager, Financial Services Applications, Analytics, Java SE, JD Edwards, MySQL, and PeopleSoft. If you use Oracle products, you should check the vulnerability matrix for your systems, review the relevant security advisories, and apply the appropriate updates promptly.