In brief: Fusion Middleware patch load significantly exceeds previous volumes; 219 of 355 vulnerabilities are remotely exploitable without authentication, requiring immediate prioritization.
Oracle’s July 2026 patch with 1,449 security updates addresses a total of 355 vulnerabilities in Fusion Middleware. Of these, ten are rated CVSS 10.0 and enable unguarded network access to critical components such as WebLogic Server, HTTP Server, and Access Manager.
With a total of 1,449 new security patches, the July update is distributed across 32 Oracle product families. Fusion Middleware was particularly heavily affected: Oracle is distributing 355 security patches, of which 219 are exploitable over the network without authentication. Ten of these gaps received the maximum rating of 10.0 on the Common Vulnerability Scoring System (CVSS) scale.
The most critical middleware vulnerabilities affect Oracle Data Integrator, Access Manager, HTTP Server, Platform Security for Java, WebCenter Content, Service Delivery Platform, and WebLogic Server Proxy Plug-in. According to Oracle, they are easily exploitable and allow attackers with mere network access over HTTP to compromise the affected systems – without any user involvement required.
In Oracle Database Server, CVE-2026-61211 proved to be severe: This 9.9-rated vulnerability resides in the RDBMS_CLOUD package and affects database versions 19.3 through 19.31 as well as 23.4.0 through 23.26.2. It allows an attacker with DBMS_CLOUD execution rights and network access to take over the system. According to Sanchit Vir Gogia (Greyhound Research), urgency is configuration-dependent: where DBMS_CLOUD is installed and comprehensively deployed, a 72-hour window remains. CVE-2026-47040, a second critical database flaw, is exploitable in Connection Manager and requires no authentication.
In addition, Oracle GoldenGate received 27 patches, nine of them without authentication requirements, and two critical vulnerabilities in TimesTen were fixed. The patch volume of 1,449 fixes marks an escalation compared to 481 patches in April 2026 and 309 one year prior. Greyhound Research recommends a phased approach by organizations based on reachability (network-exposed vs. isolated) and authentication requirements.
Source: www.csoonline.com · Published 22 July 2026
Lumi AI News — AI-assisted curation according to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.