Oracle has released its Critical Patch Update (CPU) for July 2026, a quarterly security release that fixes known vulnerabilities across its product families. This quarter’s CPU delivers 20 new security patches for JD Edwards EnterpriseOne.
Action required: Install security release updates promptly
Oracle continues to see attempts to exploit vulnerabilities for which patches are already available, and notes that some attacks succeed simply because those patches weren’t applied. This makes timely patching one of the most effective steps JD Edwards customers can take to protect your environments from preventable, known risks. As with every CPU, Oracle recommends applying these patches without delay.
Oracle releases Critical Security Patch Updates (CSPUs) separately on the third Tuesday of February, March, May, June, August, September, November, and December, with the next update planned for August 18, 2026.
Outside the regular CPU and CSPU cycles, Oracle also issues standalone Security Alerts for vulnerability fixes deemed too critical to wait for the next scheduled release. They are published as needed, and Oracle maintains a running list of all Security Alerts issued since 2021 on the Security Alerts page. It’s worth bookmarking alongside the CPU and CSPU schedules, as a Security Alert can be published at any time.
Key Resources
- JD Edwards Patch Availability (Doc ID CPU275)
- Text Form of Risk Matrix for Oracle JD Edwards
- Subscribe to Oracle Security Notifications
- Oracle Security Blog
To understand how CSPUs complement this quarterly cycle, see our earlier post: Critical Security Patch Updates for Oracle JD Edwards – June 2026.
