Summary
- Oracle’s August Critical Security Patch Update contains 943 patches covering more than 1,000 CVEs.
- More than 460 vulnerabilities are reported as remotely exploitable without authentication.
- The release is part of Oracle’s new monthly high-priority patch programme alongside its quarterly cumulative updates.
Oracle has issued 943 security patches in its August Critical Security Patch Update, addressing more than 1,000 vulnerabilities across a broad collection of enterprise products.
More than 460 of the vulnerabilities covered by the release can reportedly be exploited remotely without authentication. Individual product families contain substantial concentrations of those weaknesses: Oracle Fusion Middleware alone received 355 new security patches, including 219 vulnerabilities that Oracle says may be remotely exploitable without user credentials.
Oracle E-Business Suite received 126 new security patches, 33 of them remotely exploitable without authentication, while Enterprise Manager and Financial Services applications also include remotely reachable vulnerabilities.
The overall numbers make the release unusually large, but patch volume is not a useful measure of organisational risk on its own. Oracle technology spans databases, middleware, enterprise applications, retail and hospitality systems, and infrastructure products deployed in very different configurations.
Exposure depends on whether an affected component is actually installed, which version is running, whether the vulnerable service can be reached and what business process depends on it. The immediate task is therefore asset mapping rather than treating every CVE as an equal emergency.
Unauthenticated network exploitation remains a strong prioritisation signal because an attacker does not first need to compromise an account. Even within that group, internet accessibility, network segmentation and the sensitivity of the affected system determine which fixes should move first.
The August release also belongs to a changed Oracle patching model. Earlier in 2026 the company introduced Critical Security Patch Updates, or CSPUs, to provide targeted high-priority fixes during months that do not contain its traditional quarterly cumulative Critical Patch Updates.
Beginning in June, CSPUs are scheduled for the third Tuesday of February, March, May, June, August, September, November and December. Quarterly CPUs continue in January, April, July and October and remain cumulative.
More frequent releases reduce the time customers may wait for important fixes but increase the operational cadence for teams responsible for testing and deployment. Oracle environments often underpin business-critical applications where applying patches can require regression testing, supplier coordination and planned downtime.
That creates tension between security urgency and operational resilience. A rapidly deployed change that disrupts an enterprise application can create its own incident, while delaying a remotely exploitable vulnerability leaves a known route available to attackers.
Regulatory expectations increasingly require organisations to demonstrate that vulnerability remediation is tied to actual business exposure rather than arbitrary patch schedules. DORA and national implementations of NIS2 add pressure around technology risk and resilience, particularly where an affected system supports essential or regulated services.
The August update therefore tests the quality of the information surrounding the patch process. Organisations with accurate asset inventories, service ownership and network-exposure data can reduce more than a thousand vulnerability records into a manageable set of priorities. Those without that context face the much less efficient task of treating a large vendor advisory as a single undifferentiated security problem.




