ORACLE announced the release of 943 new security patches as part of its August 2026 Critical Security Patch Update (CSPU), addressing over 1,000 unique vulnerabilities, including more than 460 that can be exploited remotely without authentication. Among the patches, 150 are considered critical, with nearly 90 having a CVSS score of 9.8 or higher. The updates primarily affect Fusion Middleware and Hyperion, which each received 262 patches, including significant critical-severity flaws.
Other products impacted include E-Business Suite and MySQL. Oracle warns customers to apply updates promptly due to ongoing exploit attempts by threat actors.