Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Poison Claude Sells AI Tokens From Fake Accounts and Free Credits
August 5, 2026
Greatness PhaaS Bypasses Email Security, MFA to Hijack Microsoft 365 Accounts
August 5, 2026
Microsoft Awards Record $20M to 562 Researchers in Biggest Bug Bounty Year
August 5, 2026
Home/CyberSecurity News/Oracle Patches 35 Critical Vulnerabilities Across Multiple Products
CyberSecurity News

Oracle Patches 35 Critical Vulnerabilities Across Multiple Products

Key Takeaways Oracle has launched its inaugural Critical Security Patch Update (CSPU), a new, more frequent patching model. The CSPU addresses 35 critical vulnerabilities across major product lines,...

Jennifer sherman
Jennifer sherman
May 29, 2026 4 Min Read
67 0

Key Takeaways

  • Oracle has launched its inaugural Critical Security Patch Update (CSPU), a new, more frequent patching model.
  • The CSPU addresses 35 critical vulnerabilities across major product lines, including Oracle Database, Oracle REST Data Services, and Oracle E-Business Suite.
  • Several flaws, particularly in Oracle REST Data Services, carry CVSS v3.1 base scores of 10.0, indicating maximum severity and remote exploitability without authentication.
  • Organizations are strongly urged to apply these patches immediately to mitigate significant risk, as temporary workarounds are not sufficient.

Oracle has initiated a new, accelerated patching strategy with the release of its first Critical Security Patch Update (CSPU). This update delivers 35 critical security fixes across a range of its core products. Prominently affected systems include Oracle Database, Oracle REST Data Services (ORDS), Oracle Communications Unified Assurance, Oracle E-Business Suite, and Oracle Hospitality OPERA 5.

Table Of Content

  • Key Takeaways
  • Oracle Critical Security Update Details
  • Database and Application Server Vulnerabilities
  • What You Should Do

The CSPU model represents a strategic shift by Oracle to provide more timely remediation for high-priority vulnerabilities. Unlike the broader, quarterly Critical Patch Updates (CPUs), CSPUs are designed as focused releases, enabling customers to address urgent security issues more rapidly between the larger, cumulative updates.

The debut CSPU was released on May 28, 2026, marking the beginning of a new monthly security patching cadence. Oracle anticipates future CSPUs will typically be issued on the third Tuesday of each month.

While CPUs often encompass hundreds of fixes spanning numerous product families, this initial CSPU specifically targets 35 newly identified vulnerabilities that Oracle has deemed require expedited attention.

Oracle Critical Security Update Details

These essential patches cover not only Oracle’s proprietary code but also critical third-party components embedded within its products. This includes widely used software such as Apache Kafka, ActiveMQ, Tomcat, ZooKeeper, MySQL, PCRE2, libpng, and Apache HTTP Server.

Database and Application Server Vulnerabilities

Within the database ecosystem, Oracle Database Server versions 23.4.0 through 23.26.2 are receiving three new security patches targeting the Net Service component. These vulnerabilities, identified as CVE-2026-46833, CVE-2026-46834, and CVE-2026-46835, are remotely exploitable over TLS without requiring authentication. Crucially, these fixes are relevant even for client-only installations that do not host a full database server, making immediate patching vital for any environment where Oracle client libraries interface with untrusted networks or intermediary services.

Oracle REST Data Services (ORDS) versions 24.2.0 to 26.1.0 are particularly impacted, receiving 11 new security patches, alongside additional updates for its bundled third-party components. Seven of these flaws are remotely exploitable via HTTPS without user credentials, affecting core ORDS functionalities, Backend-as-a-Service, MongoAPI, and the Eclipse Jetty stack. One specific vulnerability, CVE-2026-46840, found in the Backend-as-a-Service component, carries a CVSS v3.1 base score of 10.0. This maximum severity rating signifies that successful exploitation on an exposed ORDS endpoint could lead to a complete compromise of confidentiality, integrity, and availability.

Oracle Communications Unified Assurance versions 6.1.1 through 7.0.0 are also addressed with eight new patches. Four of these vulnerabilities are remotely exploitable without authentication, impacting critical messaging and core web components.

The CSPU further delivers 12 new fixes for Oracle E-Business Suite versions 12.2.3 through 12.2.15. These patches affect modules such as Payments, Payroll, iAssets, Flow Manufacturing, and Financials Common Modules, with several vulnerabilities scoring 9.8 and 9.9 on the CVSS scale when exploited over HTTP or HTTPS.

In the hospitality sector, Oracle Hospitality OPERA 5 Property Services is affected by CVE-2026-34311, a critical remote issue with a CVSS score of 9.8, impacting multiple 5.6.x releases.

Detailed advisories, risk matrices, and CSAF feeds for automated security management are available through the Oracle Security Alert issues portal, providing comprehensive information on these CVSS-rated vulnerabilities.

Oracle’s advisory emphasizes that threat actors frequently exploit already-patched vulnerabilities when organizations delay updates. Consequently, the company strongly recommends the immediate deployment of CSPU patches across all supported versions. While temporary risk reduction might be achieved by blocking affected network protocols or restricting unnecessary privileges, Oracle cautions that such measures can disrupt application functionality and are not viable long-term substitutes for applying the underlying code patches.

What You Should Do

  • Immediately Apply Patches: Prioritize and deploy the May 2026 CSPU patches to all affected Oracle products and components, including client-only installations.
  • Review Oracle Advisories: Consult the official Oracle Security Alert issues for specific details, CVSS scores, and mitigation guidance pertinent to your environment.
  • Do Not Rely on Workarounds: Understand that blocking protocols or stripping privileges are temporary measures and not a substitute for full patching; they may also impact functionality.
  • Monitor for Future CSPUs: Be aware of Oracle’s new monthly CSPU schedule, typically on the third Tuesday of each month, and integrate these into your regular patching cycle.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurity

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Fake OpenAI Codex UI Steals Authentication Tokens

Next Post

Typosquatting npm Packages Steal Cloud and CI/CD Secrets

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical TP-Link Omada ZTP Flaws Let Attackers Hijack Routers, Execute Root Code
August 5, 2026
Critical OVSwrap Linux Vulnerability (CVE-2024-3094) Lets Attackers Gain Root
August 5, 2026
Django Patches Four High-Severity Vulnerabilities in Versions 6.0.8 and 5.2.17
August 5, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us