Full Report
Oracle addresses 241 CVEs in its second quarterly update of 2026 with 481 patches, including 34 critical updates.Key takeaways:The second Critical Patch Update (CPU) for 2026 contains fixes for 241 unique CVEs in 481 security updates 34 issues (7.1% of all patches) were assigned a critical severity rating Oracle Communications received the highest number of patches at 139, accounting for 28.9% of all patches BackgroundOn April 21, Oracle released its Critical Patch Update (CPU) for April 2026, the second quarterly update of the year. This CPU contains fixes for 241 unique CVEs in 481 security updates across 28 Oracle product families. Out of the 481 security updates published this quarter, 7.1% of patches were assigned a critical severity. High severity patches accounted for the bulk of security patches at 45.9%, followed by medium severity patches at 44.1%.This quarter's update includes 34 critical patches across 22 CVEs.SeverityIssues PatchedCVEsCritical3422High22199Medium212107Low1413Total481241AnalysisThis quarter, the Oracle Communications product family contained the highest number of patches at 139, accounting for 28.9% of the total patches, followed by Oracle Financial Services Applications at 75 patches, which accounted for 15.6% of the total patches.A full breakdown of the patches for this quarter can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication.Oracle Product FamilyNumber of PatchesRemote Exploit without AuthOracle Communications13993Oracle Financial Services Applications7559Oracle Fusion Middleware5946Oracle MySQL343Oracle PeopleSoft217Oracle E-Business Suite188Oracle Analytics1511Oracle Retail Applications1515Oracle Siebel CRM1413Oracle Java SE117Oracle GoldenGate107Oracle Enterprise Manager98Oracle Virtualization91Oracle Database Server84Oracle Utilities Applications76Oracle Hyperion64Oracle Construction and Engineering43Oracle Life Science Applications43Oracle Supply Chain42Oracle Blockchain Platform32Oracle Commerce32Oracle JD Edwards33Oracle Adapter for Eclipse RDF4J22Oracle Autonomous Health Framework21Oracle REST Data Services22Oracle Systems21Oracle TimesTen In-Memory Database11Oracle Hospitality Applications11SolutionCustomers are advised to apply all relevant patches in this quarter's CPU. Please refer to the April 2026 advisory for full details.Identifying affected systemsA list of Tenable plugins to identify these vulnerabilities will appear here as they're released. This link uses a search filter to ensure that all matching plugin coverage will appear as it is released.Get more informationOracle Critical Patch Update Advisory - April 2026Oracle April 2026 Critical Patch Update Risk MatricesOracle Advisory to CVE MapJoin Tenable's Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.
Analysis Summary
# Vulnerability: Oracle April 2026 Critical Patch Update (Multiple Vulnerabilities)
## CVE Details
- **CVE ID:** 241 unique CVEs (Specific identifiers across 28 product families including CVEs for Middleware, MySQL, and Communications)
- **CVSS Score:** Up to 9.8 (Critical)
- **CWE:** Varies (Includes flaws allowing unauthorized network exploitation)
## Affected Systems
- **Products:** 28 Oracle Product Families, most notably:
- Oracle Communications (139 patches)
- Oracle Financial Services Applications (75 patches)
- Oracle Fusion Middleware (59 patches)
- Oracle MySQL (34 patches)
- Oracle PeopleSoft, E-Business Suite, Java SE, Analytics, and Retail Applications.
- **Versions:** Multiple versions across the enterprise stack; refer to the vendor's April 2026 Risk Matrices for specific version strings.
- **Configurations:** High risk for systems accessible over a network without authentication.
## Vulnerability Description
This update addresses a massive collection of 481 security flaws. The most severe vulnerabilities allow unauthenticated remote attackers to compromise Oracle systems over a network. While specific technical details for all 241 CVEs vary, the high volume of "Remote Exploit without Auth" patches indicates flaws in network-facing protocols, APIs, and management interfaces across Oracle's communications and middleware suites.
## Exploitation
- **Status:** Vulnerabilities are currently being addressed via proactive patching; specific "in-the-wild" exploitation status for the April 2026 batch is typically disclosed in subsequent advisories.
- **Complexity:** Low to High (Varies by CVE; many are "Low" complexity remote exploits).
- **Attack Vector:** Primarily **Network**.
## Impact
- **Confidentiality:** High (Critical patches address full data exposure)
- **Integrity:** High (Risk of unauthorized data modification)
- **Availability:** High (Risk of Denial of Service and system takeover)
## Remediation
### Patches
- Users must apply the **April 2026 Critical Patch Update (CPU)**.
- Specific patches are available for each product line via the Oracle Support portal.
- Priority should be given to **Oracle Communications** and **Financial Services Applications** due to the high volume of remote-unauthenticated vulnerabilities.
### Workarounds
- Oracle generally does not provide workarounds for CPU vulnerabilities, advising instead for immediate patching.
- Interim mitigation includes restricting network access to affected services (e.g., closing ports 80/443/7001 or specific database ports to trusted IPs only).
## Detection
- **Tenable Plugins:** Use Tenable Nessus, Security Center, or Tenable.io to run scans using the "(April 2026 CPU)" filter.
- **Indicators of Compromise:** Monitor for unusual administrative logins, unexpected outbound network traffic from Oracle application servers, or unauthorized changes to system configurations.
## References
- Oracle Critical Patch Update Advisory - April 2026: hxxps://www[.]oracle[.]com/security-alerts/cpuapr2026[.]html
- Oracle April 2026 Risk Matrices: hxxps://www[.]oracle[.]com/security-alerts/cpuapr2026verbose[.]html
- Tenable Analysis: hxxps://www[.]tenable[.]com/blog/oracle-april-2026-critical-patch-update-addresses-241-cves