Oracle Key Vault 21.15 is now available with important security updates across the Oracle Key Vault software stack, including the embedded Oracle Database, Oracle Linux, Oracle APEX, Oracle REST Data Services, Oracle Java SE, and Oracle GoldenGate. Customers running Oracle Key Vault 21.14 or any earlier supported release should upgrade to Oracle Key Vault 21.15 immediately.
Oracle Key Vault protects an organization’s most sensitive assets, including Transparent Data Encryption (TDE) master keys, Oracle GoldenGate master encryption keys, Oracle wallets, Java KeyStores, SSH keys, passwords, and other keys, secrets, and credentials. A compromise of these assets could give adversaries access to encrypted data, databases, applications, servers, and other critical systems. Keeping Oracle Key Vault current with its security patches must therefore be treated as a security priority.
Protect the keys and secrets that protect your organization’s sensitive data
AI is accelerating security threats by making it easier for attackers to identify vulnerabilities, automate reconnaissance, steal credentials, and move through compromised environments. This reduces the time organizations must apply security updates after vulnerabilities become known.
In Prepare Now: Apply the Upcoming Oracle Database Release Update Immediately Upon Availability, Vipin Samar, Senior Vice President of Database Security at Oracle, recommended that customers patch not only their databases, but also the technologies that surround and protect them. Oracle Key Vault was specifically identified as part of this critical security infrastructure. Upgrading to Oracle Key Vault 21.15 is how Oracle Key Vault customers can act on that recommendation.
As attacks on operating systems become wide-spread and automated, encrypting sensitive data in Oracle Database with Transparent Data Encryption (TDE) is increasingly important. TDE helps protect database files, backups, redo logs, archived redo logs, and other data at rest if they are stolen or accessed outside the database.
However, encrypted data is protected only as long as its keys remain protected.
When a TDE master encryption key is stored in a local wallet file on the database server, an attacker who compromises the host operating system may attempt to steal both the encrypted database files and the wallet with the master encryption key. Moving this wallet into Oracle Key Vault separates the keys from the encrypted data and reduces the risk associated with storing key locally on database hosts.
Oracle Key Vault extends this protection beyond TDE. It provides centralized protection and management for security assets including:
- Oracle Database TDE master encryption keys
- Oracle GoldenGate master encryption keys
- Private keys, public keys and certificates
- Passwords and credentials
- SSH private keys
- Oracle wallets
- Java KeyStores
- Other cryptographic keys and secrets
A single Oracle Key Vault cluster protects the assets used by hundreds or thousands of databases, Oracle GoldenGate, application servers, and infrastructure endpoints across an organization’s environment, including Oracle databases running everywhere. This includes on-premises infrastructure, Exadata, OCI, Exadata Database Service on Dedicated Infrastructure (ExaDB-D), Autonomous Database on Dedicated Infrastructure (ADB-D), Autonomous Database Serverless (ADB-S), Autonomous Database on Exadata Cloud@Customer (ADB-ExaC@C), Exadata Cloud@Customer (ExaDB-C@C), Oracle Database@Azure, Oracle Database@AWS, Oracle Database@Google Cloud, and hybrid cloud environments. This makes Oracle Key Vault an essential part of an organization’s data-protection, credential-protection, and ransomware-resilience strategy. Keeping it current with the latest security updates is how organizations preserve the strength of that protection.
Security and platform updates in Oracle Key Vault 21.15
Oracle Key Vault 21.15 is a security-focused release that delivers a comprehensive set of critical security updates across the Oracle Key Vault platform, covering both the Oracle Key Vault server appliance and the Oracle Key Vault client (endpoint) software.
This update release includes Oracle Database Release Update (RU) 19.32 for the embedded Oracle Database. The CVEs addressed by this update are listed in the July 2026 Critical Patch Update.
Additional updates in this release include:
- Security and stability updates for integrated components, including Oracle APEX, Oracle REST Data Services (ORDS), Oracle Java SE, and Oracle GoldenGate.
- Security updates for the embedded Oracle Linux 8.10 operating system.
- Platform-wide stability, reliability, and maintenance improvements for Oracle Key Vault.
Delaying the upgrade leaves the key-management platform, along with the keys, credentials, wallets, and secrets it protects, without the latest available security fixes.
For complete information about changes, see the Oracle Key Vault 21.15 Release Notes.
Action required: Upgrade to Oracle Key Vault 21.15 now
All customers running Oracle Key Vault 21.14 or an earlier supported release should upgrade immediately.
Oracle Key Vault cluster architecture supports rolling upgrades. While one node is upgraded, the remaining nodes continue serving Key Vault clients, including Oracle Databases. This design ensures zero downtime for Key Vault clients during a Key Vault cluster upgrade, allowing customers to upgrade without operational disruption.
Although Oracle Key Vault 21.15 server is backward compatible with earlier versions of Oracle Key Vault endpoint software, Oracle strongly recommends upgrading the endpoint software on all Key Vault clients as soon as possible. For Oracle Database 19c deployments using Oracle RAC or Oracle Data Guard, upgrade the Oracle Key Vault endpoint software in a rolling manner to maintain database availability. For Oracle AI Database 26ai, use the “Near-Zero Downtime Endpoint Upgrade” procedure in the Oracle Key Vault 21.15 Installation and Upgrade Guide.
Before beginning, review the supported upgrade paths, prerequisites, and deployment instructions in the Oracle Key Vault 21.15 Installation and Upgrade Guide.
Prepare for more frequent security updates
Oracle Key Vault 21.15 update should not be treated as a one-time security event. As AI accelerates vulnerability discovery and attack development, organizations should expect to evaluate and deploy security updates more frequently and within shorter windows.
Keeping Oracle Key Vault current with the security updates is essential because it:
- Protects the encryption keys that keep database files, backups, and other sensitive data unreadable if they are stolen.
- Removes the risk of storing TDE master encryption keys in local wallet files on database servers.
- Secures high-value assets such as Oracle wallets, Java KeyStores, SSH private keys, passwords, credentials, and other cryptographic secrets.
- Ensures that the key-management platform itself remains protected.
Organizations should incorporate updating Oracle Key Vault into their regular security-patching processes and be prepared to deploy future security-focused updates promptly.
Upgrade or deploy Oracle Key Vault 21.15
- Existing Oracle Key Vault deployment: Download patch 39549917.
- New Oracle Key Vault installation: Download Oracle Key Vault 21.15 from Oracle Software Delivery Cloud.
- Oracle Cloud Infrastructure: Provision Oracle Key Vault 21.15 from Oracle Cloud Marketplace.
- Multicloud installation: Install Oracle Key Vault in Microsoft Azure, Amazon Web Services, or Google Cloud.
- Oracle Database Appliance: Install Oracle Key Vault on Oracle Database Appliance (ODA).
Learn more
