Oracle today released the July 2026 Critical Patch Update.

This Critical Patch Update provides security updates for a wide range of product families: Oracle Database Server, Oracle APEX, Oracle Autonomous Health Framework, Oracle Essbase, Oracle Global Lifecycle Management, Oracle GoldenGate, Oracle NoSQL Database, Oracle Spatial Studio, Oracle SQL Developer, Oracle TimesTen In-Memory Database, Oracle Application Testing Suite, Oracle Commerce, Oracle Communications, Oracle Construction and Engineering, Oracle E-Business Suite, Oracle Enterprise Manager, Oracle Financial Services Applications, Oracle Food and Beverage Applications, Oracle Fusion Middleware, Oracle Analytics, Oracle HealthCare Applications, Oracle Hospitality Applications, Oracle Java SE, Oracle JD Edwards, Oracle MySQL, Oracle PeopleSoft, Oracle Retail Applications, Oracle Siebel CRM, Oracle Supply Chain, Oracle Systems, Oracle Utilities Applications, Oracle Virtualization.

The July Critical Patch Update (CPU) is Oracle’s largest security release to date, reflecting expanded product coverage, AI-powered identification of actionable security findings, accelerated security engineering processes, and the broader scope of quarterly CPUs. The July CPU includes 1,449 security patches, addresses 1434 distinct CVEs, and spans 334 Oracle products.

Action required: Install the security release update promptly

Oracle Security Updates are released on the third Tuesday of each month. We strongly encourage you and your team – if you haven’t already – to move immediately to a monthly security patching cycle. Start by applying the updates published in the July CPU.
Transitioning to a monthly security patching cadence may require updates to existing operational processes. If your organization needs assistance planning or executing that transition, Oracle Customer Success Services (CSS) can reduce your security risk for the database and Oracle technologies with vulnerability assessments, patches, upgrades, migrations to cloud, and hardening.

For more information about the July 2026 Critical Patch Update, customers should refer to the Critical Patch Update advisory located at https://www.oracle.com/security-alerts/cpujul2026.html and the executive summary published on My Oracle Support (Doc ID CPU160).

For more information about the Critical Patch Update program, see the security vulnerability remediation practices page located on the Oracle Trust Center.