Oracle’s quarterly Critical Patch Update just delivered its biggest patch load yet, and according to Oracle’s own July 2026 advisory, the July release covers 1,449 security patches addressing 1,434 unique CVEs across 334 products, led by E-Business Suite (410 patches), Fusion Middleware (355), Communications (168), and PeopleSoft (84). Roughly 600 of the fixes address vulnerabilities that can be exploited remotely without any authentication at all.
The scale matters because Oracle products are not a theoretical target. Oracle’s advisory notes plainly that “attackers have been successful because targeted customers had failed to apply available Oracle patches,” a warning that carries extra weight after this year’s Cl0p campaign against Oracle E-Business Suite customers and a separate PeopleSoft zero-day, both of which turned unpatched Oracle deployments into real breaches rather than hypothetical exposure. With hundreds of this quarter’s fixes reachable without credentials, the window between “patch available” and “exploited in the wild” is not one most security teams can afford to test.
What is easy to miss in the headline count is why it keeps climbing. Oracle disclosed earlier this year that it now uses frontier AI systems, including Anthropic’s Claude Mythos and OpenAI’s most capable models, to accelerate vulnerability discovery across its own code, Oracle Health, and the open-source components it depends on, and outside researchers are credited with only a few dozen of this quarter’s finds. That means the CPU’s growth is now driven less by more code shipping and more by AI-assisted review surfacing flaws humans were not finding fast enough, the same dynamic CyberTech reported when a record Patch Tuesday forced security teams to trade patching everything for triage. Vendors adopting AI-assisted bug hunting will keep growing patch volumes structurally, and security teams still triaging CPUs patch-by-patch rather than by actual exposure will fall further behind every quarter, not just this one.
Source: Oracle