Oracle Patches 35 Critical Vulnerabilities Across Multiple Products
Key Takeaways Oracle has launched its inaugural Critical Security Patch Update (CSPU), a new, more frequent patching model. The CSPU addresses 35 critical vulnerabilities across major product lines,...
Key Takeaways
- Oracle has launched its inaugural Critical Security Patch Update (CSPU), a new, more frequent patching model.
- The CSPU addresses 35 critical vulnerabilities across major product lines, including Oracle Database, Oracle REST Data Services, and Oracle E-Business Suite.
- Several flaws, particularly in Oracle REST Data Services, carry CVSS v3.1 base scores of 10.0, indicating maximum severity and remote exploitability without authentication.
- Organizations are strongly urged to apply these patches immediately to mitigate significant risk, as temporary workarounds are not sufficient.
Oracle has initiated a new, accelerated patching strategy with the release of its first Critical Security Patch Update (CSPU). This update delivers 35 critical security fixes across a range of its core products. Prominently affected systems include Oracle Database, Oracle REST Data Services (ORDS), Oracle Communications Unified Assurance, Oracle E-Business Suite, and Oracle Hospitality OPERA 5.
Table Of Content
The CSPU model represents a strategic shift by Oracle to provide more timely remediation for high-priority vulnerabilities. Unlike the broader, quarterly Critical Patch Updates (CPUs), CSPUs are designed as focused releases, enabling customers to address urgent security issues more rapidly between the larger, cumulative updates.
The debut CSPU was released on May 28, 2026, marking the beginning of a new monthly security patching cadence. Oracle anticipates future CSPUs will typically be issued on the third Tuesday of each month.
While CPUs often encompass hundreds of fixes spanning numerous product families, this initial CSPU specifically targets 35 newly identified vulnerabilities that Oracle has deemed require expedited attention.
Oracle Critical Security Update Details
These essential patches cover not only Oracle’s proprietary code but also critical third-party components embedded within its products. This includes widely used software such as Apache Kafka, ActiveMQ, Tomcat, ZooKeeper, MySQL, PCRE2, libpng, and Apache HTTP Server.
Database and Application Server Vulnerabilities
Within the database ecosystem, Oracle Database Server versions 23.4.0 through 23.26.2 are receiving three new security patches targeting the Net Service component. These vulnerabilities, identified as CVE-2026-46833, CVE-2026-46834, and CVE-2026-46835, are remotely exploitable over TLS without requiring authentication. Crucially, these fixes are relevant even for client-only installations that do not host a full database server, making immediate patching vital for any environment where Oracle client libraries interface with untrusted networks or intermediary services.
Oracle REST Data Services (ORDS) versions 24.2.0 to 26.1.0 are particularly impacted, receiving 11 new security patches, alongside additional updates for its bundled third-party components. Seven of these flaws are remotely exploitable via HTTPS without user credentials, affecting core ORDS functionalities, Backend-as-a-Service, MongoAPI, and the Eclipse Jetty stack. One specific vulnerability, CVE-2026-46840, found in the Backend-as-a-Service component, carries a CVSS v3.1 base score of 10.0. This maximum severity rating signifies that successful exploitation on an exposed ORDS endpoint could lead to a complete compromise of confidentiality, integrity, and availability.
Oracle Communications Unified Assurance versions 6.1.1 through 7.0.0 are also addressed with eight new patches. Four of these vulnerabilities are remotely exploitable without authentication, impacting critical messaging and core web components.
The CSPU further delivers 12 new fixes for Oracle E-Business Suite versions 12.2.3 through 12.2.15. These patches affect modules such as Payments, Payroll, iAssets, Flow Manufacturing, and Financials Common Modules, with several vulnerabilities scoring 9.8 and 9.9 on the CVSS scale when exploited over HTTP or HTTPS.
In the hospitality sector, Oracle Hospitality OPERA 5 Property Services is affected by CVE-2026-34311, a critical remote issue with a CVSS score of 9.8, impacting multiple 5.6.x releases.
Detailed advisories, risk matrices, and CSAF feeds for automated security management are available through the Oracle Security Alert issues portal, providing comprehensive information on these CVSS-rated vulnerabilities.
Oracle’s advisory emphasizes that threat actors frequently exploit already-patched vulnerabilities when organizations delay updates. Consequently, the company strongly recommends the immediate deployment of CSPU patches across all supported versions. While temporary risk reduction might be achieved by blocking affected network protocols or restricting unnecessary privileges, Oracle cautions that such measures can disrupt application functionality and are not viable long-term substitutes for applying the underlying code patches.
What You Should Do
- Immediately Apply Patches: Prioritize and deploy the May 2026 CSPU patches to all affected Oracle products and components, including client-only installations.
- Review Oracle Advisories: Consult the official Oracle Security Alert issues for specific details, CVSS scores, and mitigation guidance pertinent to your environment.
- Do Not Rely on Workarounds: Understand that blocking protocols or stripping privileges are temporary measures and not a substitute for full patching; they may also impact functionality.
- Monitor for Future CSPUs: Be aware of Oracle’s new monthly CSPU schedule, typically on the third Tuesday of each month, and integrate these into your regular patching cycle.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.