News

Urgent action required · active exploitation confirmed

Oracle Releases the July 2026 Critical Patch Update

Fusion Middleware, PeopleSoft, E-Business Suite and Oracle Communications lead a record 1,455 new security patches.

Highlights

  • Oracle’s July 2026 CPU ships 1,455 new security patches, the largest Critical Patch Update Oracle has issued to date.
  • The highest score this quarter is a perfect CVSS 10.0, affecting Oracle Access Manager, WebLogic Server and Oracle Coherence within Fusion Middleware.
  • PeopleSoft is the emergency priority. CVE-2026-35278 and CVE-2026-35273 (both CVSS 9.8) are under active exploitation by the ShinyHunters extortion group, which claims to have compromised more than 300 PeopleSoft servers across 100+ organizations since late May 2026.
  • Fusion Middleware receives 359 patches (224 remotely exploitable without authentication), the largest single-family total in this CPU. WebLogic, Identity Manager and WebCenter Capture each carry CVSS 9.9 unauthenticated RCE flaws.
  • E-Business Suite receives 416 patches (63 remotely exploitable), reflecting sustained attacker interest after the 2025 Cl0p campaign and a separately exploited flaw patched last month.
  • Java SE ships 20 patches (18 remotely exploitable) with a comparatively modest maximum CVSS of 7.8, mostly affecting availability rather than confidentiality or integrity.
  • Action: patch internet-facing PeopleSoft, Fusion Middleware (WebLogic, Identity Manager, Access Manager) and E-Business Suite this week. Treat the Database Server 9.9 flaw as high priority even though it is not yet reported under active exploitation.

Commentary

The Oracle Critical Patch Update (CPU) for July 2026 contains 1,455 new security patches spanning more than two dozen product families, making it the largest quarterly release Oracle has published. The update is cumulative, meaning it folds in the May 28 and June 16, 2026 monthly Critical Security Patch Updates (CSPU) as well as the out-of-band Security Alert issued June 10, 2026 for the PeopleSoft PeopleTools vulnerability now tracked as CVE-2026-35273.

Unlike the April 2026 CPU, which topped out at CVSS 9.8, this release includes vulnerabilities rated a full 10.0 in Fusion Middleware. It also arrives in the middle of a live, named extortion campaign against PeopleSoft, giving this cycle a different risk profile than a typical quarterly update: the most urgent items are not necessarily the ones with the highest raw score, but the ones already being used against real organizations.

Security teams should sequence their response by exploitation status first and CVSS score second: PeopleSoft patching is the immediate priority, followed by internet-facing Fusion Middleware and E-Business Suite components, with the CVSS 9.9 Database Server flaw and the remaining product families following close behind.

Critical CVSS Summary (Score 9.0+)

The vulnerabilities below carry a CVSS base score of 9.0 or higher, are remotely exploitable over the network without authentication, and should be treated as the top patching priorities for this cycle.

CVE IDCVSSAffected Product FamiliesVulnerability / Impact
CVE-2026-352739.8PeopleSoft PeopleTools (Environment Management Hub)Unauthenticated RCE. Under active exploitation by ShinyHunters since late May 2026; disclosed via out-of-band alert on June 10, 2026.
CVE-2026-352789.8PeopleSoft PeopleTools (Performance Monitor / EMHub)Pre-authentication RCE, chained with CVE-2026-35273 in the same active ShinyHunters intrusions.
Multiple10.0Fusion Middleware (Access Manager, WebLogic Server, Coherence)Highest score in this CPU. Unauthenticated compromise of identity, clustering and web-tier infrastructure.
CVE-2026-352639.9Fusion Middleware / WebLogic ServerUnauthenticated RCE via WebLogic’s T3/IIOP protocol handling.
CVE-2026-352689.9Fusion Middleware / Identity ManagerUnauthenticated remote code execution.
CVE-2026-35280 / CVE-2026-352819.9Fusion Middleware / WebCenter CaptureUnauthenticated remote code execution.
Multiple9.9Oracle Database Server (19.3–19.31, 21.3–21.22, 23.4.0–23.26.2)Highest Database Server score to date. Not reported as exploited in the wild as of publication.
Multiple9.9Oracle CommerceThird-party component flaws, remotely exploitable without authentication.
Multiple9.8Oracle E-Business SuiteContinued focus area following 2025–2026 zero-day activity against EBS.
Multiple9.8Oracle Communications (168 patches, 122 remote)Largest patch count outside Fusion Middleware; signaling and billing components affected.
Multiple9.8Oracle Financial Services ApplicationsUnauthenticated, network-accessible flaws in Oracle Banking products.
Multiple9.8Oracle Enterprise Manager / Retail ApplicationsUnauthenticated remote vulnerabilities across both families.

Focus Area: Key Product Families

Oracle Fusion Middleware

Fusion Middleware received 359 new security patches, the largest total of any product family in this CPU, with 224 remotely exploitable without authentication.

Highest severity: a CVSS 10.0 affects Oracle Access Manager, WebLogic Server and Oracle Coherence. Three additional unauthenticated RCE flaws are rated 9.9: CVE-2026-35263 (WebLogic Server, via the T3/IIOP protocol), CVE-2026-35268 (Identity Manager) and CVE-2026-35280 / CVE-2026-35281 (WebCenter Capture).

Operational risk: WebLogic’s T3/IIOP channel has a long history as an exploitation vector for Java deserialization attacks, and Identity Manager has already been the subject of two separate 9.8-class RCEs in the past twelve months (CVE-2025-61757 and CVE-2026-21992). Organizations with internet-reachable WebLogic consoles or OIM/OWSM endpoints should treat this CPU as urgent.

Oracle PeopleSoft, active exploitation

PeopleSoft received 84 new security patches, with 45 remotely exploitable without authentication and a highest CVSS of 9.9. This is the most consequential product family in the July release because two of its vulnerabilities are already being used in live attacks.

CVE-2026-35273 (CVSS 9.8) sits in the PeopleTools Environment Management Hub and was disclosed as an out-of-band Oracle Security Alert on June 10, 2026, after the ShinyHunters group had already begun exploiting it as a zero-day. It allows unauthenticated remote code execution over HTTP.

CVE-2026-35278 (CVSS 9.8), fixed in this CPU, affects the PeopleTools Performance Monitor and EMHub components and is being chained with CVE-2026-35273 by the same threat actor to gain and expand access.

Impact: ShinyHunters claims to have compromised more than 300 PeopleSoft instances across upwards of 100 organizations, heavily weighted toward higher education, exfiltrating HR, payroll and financial data. Any organization that ran an exposed PeopleSoft instance during the exploitation window should assume compromise and investigate, even after patching.

Dependency warning: PeopleSoft deployments inherit exposure from the underlying Fusion Middleware and Database components; apply the corresponding patches to those layers as well.

Oracle E-Business Suite (EBS)

EBS received 416 new security patches this cycle, the largest EBS patch batch on record, with 63 remotely exploitable without authentication and a highest CVSS of 9.8.

This continues a pattern that began with the October 2025 zero-day (CVE-2025-61882) exploited by the Cl0p group, and more recently CVE-2026-46817, a CVSS 9.8 privilege-management flaw in Oracle Payments that was confirmed under active exploitation against internet-facing EBS honeypots after Oracle shipped a fix in last month’s Critical Security Patch Update.

Dependency warning: EBS relies on Oracle Database and Fusion Middleware components, so the corresponding Database and Fusion Middleware patches from this CPU should be applied alongside the EBS-specific fixes.

Oracle Java SE

Java SE contains 20 new security patches this cycle, with 18 remotely exploitable without authentication. The highest CVSS affecting Java SE is 7.8, a notably lower ceiling than the flagship enterprise products, and impact is concentrated on availability rather than full system compromise.

No Java SE vulnerability in this CPU has been reported as under active exploitation as of publication, but organizations running long-lived JVM processes, mutual TLS, or JNDI lookups against untrusted sources should still review exposure and patch on a normal cycle.

Other Affected Families

  • Oracle Communications: 168 patches, 122 remotely exploitable, highest CVSS 9.8, spanning billing, revenue management and communications broker components.
  • Oracle Database Server: 16 patches, 7 remotely exploitable, highest CVSS 9.9 across all currently supported releases (19.3–19.31, 21.3–21.22, 23.4.0–23.26.2). Not reported exploited in the wild as of this bulletin.
  • Oracle Commerce: 39 patches, 27 remotely exploitable, highest CVSS 9.9.
  • Oracle Financial Services Applications: 23 patches, reported highest CVSS 9.8, concentrated in Oracle Banking products.
  • Oracle Enterprise Manager: 27 patches, 13 remotely exploitable, highest CVSS 9.8.
  • Oracle Retail Applications: 22 patches, 20 remotely exploitable, highest CVSS 9.8.
  • Oracle VirtualBox: CVE-2026-35275 (CVSS 7.5), a guest-to-host escape relevant to anyone running untrusted virtual machines.

Threat Intelligence: Active Attacks and Zero-Days

PeopleSoft is the clear emergency of this CPU. The ShinyHunters campaign against CVE-2026-35273 began before Oracle’s June 10, 2026 out-of-band alert, meaning affected organizations were exposed as a true zero-day. Oracle’s July CPU folds in the permanent fix for that flaw and adds the newly disclosed CVE-2026-35278, which the same actor is chaining for lateral movement and data theft.

Oracle E-Business Suite remains a secondary but still active area of concern. CVE-2026-46817, patched last month, was confirmed under opportunistic exploitation against exposed EBS instances even after a fix was available, underscoring that unpatched systems remain targeted long after disclosure.

By contrast, the CVSS 9.9 Oracle Database Server flaw and the CVSS 10.0 Fusion Middleware issues carry the highest theoretical severity in this release but have not been reported as exploited as of publication. Security teams should not let raw score alone reorder priorities: confirmed exploitation against PeopleSoft outweighs a higher score with no known attacker activity.

A Faster Patch Cadence

Since earlier in 2026, Oracle has supplemented the quarterly CPU with monthly Critical Security Patch Updates (CSPU) for several product families, including Fusion Middleware, E-Business Suite and Oracle Communications. This July CPU is a cumulative release that folds in the May and June CSPUs. Organizations that track only the quarterly CPU still receive the full fix set, but those that adopt the monthly cadence can close critical gaps within roughly 30 days of disclosure rather than waiting up to 90. The next monthly CSPU is expected August 18, 2026.

Frequently Asked Questions

What is the Oracle Critical Patch Update and why is July’s so large?

The July Critical Patch Update (CPU) is Oracle’s largest security release to date, reflecting expanded product coverage, AI-powered identification of actionable security findings, accelerated security engineering processes, and the broader scope of quarterly CPUs. The Critical Patch Update framework for July 2026 contains 1,455 new security patches, the largest quarterly total Oracle has issued, driven mainly by Fusion Middleware (359 patches) and E-Business Suite (416 patches).

Is anything in this CPU being actively exploited right now?

Yes. CVE-2026-35273 and CVE-2026-35278 in Oracle PeopleSoft are under active exploitation by the ShinyHunters group. A separate E-Business Suite flaw, CVE-2026-46817, was also confirmed exploited after last month’s fix shipped. No other vulnerability in this CPU has been publicly confirmed as exploited as of publication.

What is the ShinyHunters PeopleSoft campaign, and could we already be compromised?

ShinyHunters is a data-extortion group that has exploited CVE-2026-35273 as a zero-day since late May 2026, and is now chaining it with CVE-2026-35278 to gain and expand access to PeopleSoft servers. The group claims over 300 compromised instances across 100-plus organizations, with universities disproportionately affected. If your PeopleSoft instance was internet-facing and unpatched during this window, treat it as potentially compromised and investigate independently of applying the patch.

Should we prioritize the CVSS 10.0 Fusion Middleware issues or the CVSS 9.8 PeopleSoft issues first?

Prioritize PeopleSoft first. Confirmed, active exploitation against real organizations is a stronger urgency signal than a higher theoretical CVSS score with no known attacker activity. Fusion Middleware should follow immediately after, given its unauthenticated 10.0 and 9.9 flaws and its role as shared infrastructure for other Oracle products, including PeopleSoft and E-Business Suite.

Does the CVSS 9.9 Oracle Database Server flaw need emergency treatment?

It affects every currently supported Database Server release and should be scheduled promptly, but as of this bulletin it has not been reported as exploited in the wild. Most organizations can sequence it just behind PeopleSoft, Fusion Middleware and E-Business Suite rather than treating it as a same-day emergency.

Is Java SE as urgent as the other product families this quarter?

No. Java SE’s highest CVSS this cycle is 7.8, well below the 9.8 to 10.0 range affecting the enterprise application families, and impact is concentrated on availability. Apply the Java SE patches on a normal cycle unless you run long-lived JVMs, mutual TLS or JNDI lookups against untrusted sources, which warrant closer review.

What changed with Oracle’s patch release cadence in 2026?

Oracle now issues monthly Critical Security Patch Updates for several product families in addition to the quarterly CPU. The July CPU is cumulative and includes the May and June CSPUs. Organizations that adopt the monthly cadence can reduce their exposure window for critical flaws from roughly 90 days to about 30.

Where can we find full patch availability details and patch IDs?

Oracle’s official advisory, including the complete risk matrices and links to product-specific Patch Availability Documents, is published at oracle.com/security-alerts/cpujul2026.html. Consult My Oracle Support for the patch IDs and installation instructions specific to your product versions.

For More Information

Waratek customers should contact customersuccess@waratek.com for guidance on which RASP rules already cover CVEs in the July 2026 CPU.

Prospects evaluating Waratek can contact sales@waratek.com for a protection assessment.

Source advisory: Oracle Critical Patch Update Advisory - July 2026

This bulletin is a security news summary compiled by Waratek for customers and prospects from Oracle's published advisory and public reporting on active exploitation. It is not an official Oracle publication. All Oracle product names are trademarks of Oracle.

About Waratek

Waratek offers Waratek IAST+RASP, the only compiler-based, runtime application tools that find vulnerabilities in the pre-production development pipeline, block attacks in production, and virtually patch flaws with no downtime or source code changes. Waratek IAST watches code execute to identify security flaws with absolute certainty, eliminating the “guesswork” and alert fatigue associated with traditional scanners. Waratek RASP intercepts and terminates unsafe operations at the JVM level, stopping attempts to change app behavior in attacks aimed at known and Zero Day vulnerabilities. Waratek is a trusted partner for organizations in global financial services, hospitality, healthcare, technology and other industries. Waratek has offices in Dublin, Ireland and Chicago, Illinois.

Share Article