socradar.io 22 Jan 2026, 08:12 UTC

Oracle January 2026 CPU Delivers 337 Security Patches Including CVE-2025-66516 & CVE-2026-21962

CyberSIXT Evidence Panel

ORACLE’S January 2026 CPU delivers 337 security patches across more than 30 product families, with around 230 unique CVEs addressed by the patches. The update includes two vulnerabilities with maximum severity, both remotely exploitable without authentication: CVE-2025-66516 (Apache Tika) and CVE-2026-21962 (WebLogic Server Proxy Plug-in).

Oracle lists CVE-2025-66516 as CVSS 10.0 for multiple products, including the Oracle Business Process Management Suite Runtime Engine and Oracle Middleware Common Libraries and Tools, and notes that fixes may span more than one product family due to shared libraries. CVE-2026-21962 affects the WebLogic Server Proxy Plug-in for Apache HTTP Server and Microsoft IIS, linked to Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in, with affected versions specified.

There are no known zero-day vulnerabilities in this CPU, according to Oracle, though attackers have previously exploited patched flaws when updates were not applied; timely deployment is still advised, and product families such as Oracle Communications, Fusion Middleware, and Financial Services Applications are among those with the most patches. According to Oracle’s official January 2026 Critical Patch Update advisory.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline