Full Report
Oracle addresses 925 CVEs in its August 2026 Critical Security Patch Update with 943 patches, including 154 critical updates.Key TakeawaysThe August 2026 Critical Security Patch Update (CSPU) contains fixes for 925 unique CVEs in 943 security updates154 issues (16.3% of all patches) were assigned a critical severity ratingOracle Fusion Middleware received the highest number of patches at 262, accounting for 27.8% of all patchesBackgroundOn August 18, Oracle released its Critical Security Patch Update (CSPU) for August 2026. Beginning in May 2026, Oracle introduced CSPUs as a monthly release cycle that sits between the larger quarterly Critical Patch Updates (CPUs), addressing a focused set of high-severity issues on a faster cadence. This CSPU contains fixes for 925 unique CVEs in 943 security updates across 23 Oracle product families, a nearly fourfold increase in patch volume compared to the June 2026 CSPU, which addressed 243 CVEs in 245 patches across 11 product families.To put that in context against the quarterly CPUs: the April 2026 CPU contained 481 patches across 241 CVEs, and the July 2026 CPU, the largest CPU release of 2026, contained 1,449 patches across 1,235 CVEs. August's CSPU at 943 patches sits well above the April CPU and represents roughly 65% of July's quarterly volume, a striking figure for what is nominally a targeted between-cycle release. The expansion to 23 product families (up from 11 in June) further blurs the line between CSPU and CPU in terms of scope.Out of the 943 security updates published, 16.3% of patches were assigned a critical severity. High severity patches accounted for the bulk of security patches at 59%, followed by medium severity patches at 21%.This month's update includes 154 critical patches across 151 CVEs.SeverityIssues PatchedCVEsCritical154151High556541Medium198198Low3535Total943925AnalysisThis month's update saw the Oracle Fusion Middleware product family contain the highest number of patches at 262, accounting for 27.8% of the total patches, followed by Oracle Hyperion at 262 patches, which accounted for 27.8% of the total patches.A full breakdown of the patches for this CSPU can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication.Oracle Product FamilyNumber of PatchesRemote Exploit without AuthOracle Fusion Middleware262182Oracle Hyperion262107Oracle E-Business Suite12027Oracle Commerce6647Oracle Siebel CRM5021Oracle Supply Chain4618Oracle Virtualization212Oracle Analytics163Oracle PeopleSoft157Oracle Communications139Oracle Enterprise Manager116Oracle MySQL95Oracle Financial Services Applications86Oracle Autonomous Health Framework72Oracle Application Testing Suite73Oracle Database Server64Oracle JD Edwards62Oracle Java SE54Oracle Retail Applications55Oracle Essbase43Oracle Food and Beverage Applications22Oracle Construction and Engineering11Oracle Hospitality Applications11SolutionPatches for all affected products are available in the August 2026 advisory.Identifying affected systemsA list of Tenable plugins to identify these vulnerabilities will appear here as they're released. This link uses a search filter so that all matching plugin coverage appears as it is released.Get more informationOracle Critical Security Patch Update Advisory - August 2026Oracle August 2026 Critical Security Patch Update Risk MatricesOracle Advisory to CVE MapJoin Tenable's Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.
Analysis Summary
# Vulnerability: Oracle August 2026 Critical Security Patch Update (CSPU)
## CVE Details
- **CVE ID:** 925 unique CVEs addressed (Individual IDs range across 23 product families)
- **CVSS Score:** Up to 10.0 (Critical)
- **CWE:** Varies by product; includes multiple weaknesses allowing remote code execution, unauthorized data access, and denial of service.
## Affected Systems
- **Products:** 23 Oracle Product Families including:
- Oracle Fusion Middleware (262 patches)
- Oracle Hyperion (262 patches)
- Oracle E-Business Suite (120 patches)
- Oracle Commerce (66 patches)
- Oracle Siebel CRM (50 patches)
- Oracle Supply Chain (46 patches)
- Oracle Database Server, Java SE, MySQL, and Virtualization.
- **Versions:** Multiple supported versions as listed in the August 2026 Advisory.
- **Configurations:** Systems accessible over a network without authentication are at highest risk (e.g., 182 Fusion Middleware vulnerabilities).
## Vulnerability Description
This monthly Critical Security Patch Update (CSPU) addresses a massive volume of security flaws. The update focuses heavily on **Fusion Middleware** and **Hyperion**, which together account for over 55% of the total patches. Many of these flaws allow for **Remote Exploit without Authentication**, meaning an attacker can compromise the system over the network without needing valid credentials. The vulnerabilities range from memory corruption and injection flaws to improper access controls.
## Exploitation
- **Status:** Not specified as "exploited in the wild" in the summary, but high volume suggests a broad attack surface.
- **Complexity:** Low to High (Varies by CVE).
- **Attack Vector:** Primarily **Network** (Significant number of patches address "Remote Exploit without Auth").
## Impact
- **Confidentiality:** Critical (Complete disclosure of sensitive data possible).
- **Integrity:** Critical (Total modification of system data/logic possible).
- **Availability:** Critical (Complete system shutdown or denial of service possible).
## Remediation
### Patches
Oracle has released **943 patches**. Organizations should prioritize the **154 critical severity updates**.
- **Oracle Fusion Middleware:** 262 patches
- **Oracle Hyperion:** 262 patches
- **Oracle E-Business Suite:** 120 patches
- Refer to the Oracle August 2026 Advisory for specific version-mapping.
### Workarounds
- **Network Segmentation:** Isolate affected middleware and database servers from the public internet.
- **Access Control:** Restrict network access to only trusted IPs for management interfaces.
- **Disable Unused Services:** Turn off components/services within product suites that are not actively required for business operations.
## Detection
- **Indicators of Compromise:** Unusual administrative logins, unauthorized configuration changes in Fusion Middleware, or unexpected outbound traffic from Hyperion servers.
- **Detection Methods:**
- Use **Tenable Plugins** filtered for "(August 2026 CSPU)".
- Scan environments using updated vulnerability signatures to identify missing Oracle patches.
## References
- **Vendor Advisory:** hxxps[://]www[.]oracle[.]com/security-alerts/cspuaug2026[.]html
- **Risk Matrices:** hxxps[://]www[.]oracle[.]com/security-alerts/cspuaug2026verbose[.]html
- **Tenable Analysis:** hxxps[://]www[.]tenable[.]com/blog/oracle-august-2026-critical-security-patch-update-cspu-addresses-925-cves