Oracle’s July update fixes ten 10.0 vulnerabilities in Fusion Middleware
- The update addresses significant vulnerabilities in Fusion Middleware and Oracle Database Server, including ten flaws that received a perfect 10.0 score on the Common Vulnerability Scoring System (CVSS),...
- The volume of this release is the largest in the company's history.
- Fusion Middleware was the most heavily impacted product family, receiving patches for 355 security vulnerabilities.
The update addresses significant vulnerabilities in Fusion Middleware and Oracle Database Server, including ten flaws that received a perfect 10.0 score on the Common Vulnerability Scoring System (CVSS), according to the company’s patch update statement.
The volume of this release is the largest in the company’s history. Sanchit Vir Gogia, chief analyst at Greyhound Research, noted that the 1,449 patches far exceed the 481 released in April 2026 and the 309 released a year prior.
Fusion Middleware Security Risks
Fusion Middleware was the most heavily impacted product family, receiving patches for 355 security vulnerabilities. Oracle reported that 219 of these are remotely exploitable without authentication, meaning attackers can target them over a network without needing user credentials.
These vulnerabilities allow unauthenticated attackers with HTTP network access to compromise several systems, including Oracle Weblogic Server Proxy Plug-in, Oracle HTTP Server, Oracle Access Manager, Oracle Data Integrator, Oracle Platform Security for Java, WebCenter Content, and the Service Delivery Platform, according to the company statement.
Critical Oracle Database Server Flaws
The flagship database product contains a severe vulnerability, CVE-2026-61211, located in the RDBMS component’s DBMS_CLOUD package. This flaw carries a CVSS score of 9.9 and allows a low-privileged attacker with Execute DBMS_CLOUD privilege and network access via Oracle Net to compromise the RDBMS.
Oracle warned that successful attacks on this vulnerability can result in a total takeover of the RDBMS and may significantly impact additional products. The flaw affects Database Server versions 19.3 through 19.31 and 23.4.0 through 23.26.2.
Sanchit Vir Gogia stated that the 9.9 score is serious but conditional, as exposure depends on whether DBMS_CLOUD is installed and the specific network access lists in place. He suggested a 72-hour window for emergency patching where the package is broadly granted and reachable.
Cybersecurity researcher Vibhum Dubey said the flaw is concerning because database servers typically hold an organization’s most valuable data. Dubey stated, I don’t think this is the kind of issue you leave until the next routine maintenance window if your environment is exposed.
Additionally, CVE-2026-7383 is an OpenSSL-related TLS vulnerability affecting both the Autonomous Health Framework and Database Server. Oracle’s fix for this CVE also resolves 19 related OpenSSL vulnerabilities.
Impact on Other Product Families
Oracle GoldenGate received 27 new patches, with nine requiring no authentication to exploit. This includes CVE-2026-2332, a flaw in the Big Data and Application Adapters component linked to Eclipse Jetty.
The update also included two critical flaws in the TimesTen in-memory database. Other product families receiving updates include:
- E-Business Suite, PeopleSoft, and Siebel
- JD Edwards and MySQL
- WebLogic Server and Solaris
- VM VirtualBox, Retail Applications, and Utilities Applications
- Communications products
Operational Challenges and Triage
Gogia warned against patching by product logo instead of trust boundary, specifically regarding E-Business Suite. He noted that exposure for E-Business Suite may exist in underlying Database and Fusion Middleware versions that sit outside the E-Business Suite matrix.
Vibhum Dubey observed that patching in large enterprises is often an operational problem rather than a technical one, requiring alignment between database administrators, infrastructure teams, application owners, and change advisory boards.
Niyati Daftary, principal analyst at Gartner, stated that patching has shifted from a race to remediate every vulnerability to a discipline of reducing business risk. She recommended prioritizing internet-facing assets and mission-critical systems, noting that CVSS scores measure theoretical severity rather than actual enterprise risk.
The July release is the third quarterly Critical Patch Update of 2026. It follows the introduction of a monthly Critical Security Patch Update program in May. Gogia explained that the quarterly updates remain cumulative, while the monthly updates now layer on top of them.
Oracle has scheduled its next cumulative Critical Patch Update for Oct. 20, 2026. Smaller Critical Security Patch Updates are scheduled for Aug. 18 and Sept. 15.
