Oracle Critical Security Patch Update Pre-Release Announcement - August 2026

 

Description

This Critical Security Patch Update Pre-Release Announcement provides advance information about the Oracle Critical Security Patch Update for August 2026, which will be released on Tuesday, August 18, 2026.  While this Pre-Release Announcement is as accurate as possible at the time of publication, the information it contains may change before publication of the Critical Security Patch Update Advisory.

A Critical Security Patch Update (CSPU) provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption. Critical Security Patch Updates complement Oracle’s existing quarterly cumulative Critical Patch Updates (CPUs). This Critical Security Patch Update addresses 945 new security patches. Some of the vulnerabilities addressed in this Critical Security Patch Update affect multiple products. Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Critical Security Patch Update patches as soon as possible.

Executive Summaries

Oracle Database Server Executive Summary

This Critical Security Patch Update contains 5 new security patches for Oracle Database Products.  4 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  None of these patches are applicable to client-only installations, i.e., installations that do not have the Oracle Database Server installed.

The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Database Server is 9.6.

The Oracle Database Server components and versions affected by vulnerabilities that are addressed in this Critical Security Patch Update are:

  • Oracle Database Server, versions 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3

Oracle Autonomous Health Framework Executive Summary

This Critical Security Patch Update contains 7 new security patches for Oracle Autonomous Health Framework.  2 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. 

The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Autonomous Health Framework is 8.8.

The Oracle Autonomous Health Framework products and versions affected by vulnerabilities that are addressed in this Critical Security Patch Update are:

  • Oracle Autonomous Health Framework, versions 26-26.1.0, 26.2.0, 26.3.1, 26.5.0, 26.5.2

Oracle Essbase Executive Summary

This Critical Security Patch Update contains 4 new security patches for Oracle Essbase.  3 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. 

The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Essbase is 9.8.

The Oracle Essbase products and versions affected by vulnerabilities that are addressed in this Critical Security Patch Update are:

  • Oracle Essbase, version 21.8.1.0.0

Oracle Application Testing Suite Executive Summary

This Critical Security Patch Update contains 7 new security patches for Oracle Application Testing Suite.  3 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. 

The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Application Testing Suite is 9.1.

The Oracle Application Testing Suite components and versions affected by vulnerabilities that are addressed in this Critical Security Patch Update are:

  • Oracle Application Testing Suite, version 13.3.0.1

Oracle Commerce Executive Summary

This Critical Security Patch Update contains 66 new security patches for Oracle Commerce.  47 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. 

The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Commerce is 9.8.

The Oracle Commerce products and versions affected by vulnerabilities that are addressed in this Critical Security Patch Update are:

  • Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0
  • Oracle Commerce Platform, version 11.4.0

Oracle Communications Executive Summary

This Critical Security Patch Update contains 13 new security patches for Oracle Communications.  8 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. 

The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Communications is 9.8.

The Oracle Communications products and versions affected by vulnerabilities that are addressed in this Critical Security Patch Update are:

  • Management Cloud Engine, version 25.2.0.0.10
  • Oracle Communications ASAP, versions 7.4.1, 8.0.0
  • Oracle Communications Unified Assurance, versions 6.1.1-7.0.0
  • Oracle Communications Unified Inventory Management, versions 7.5.0, 7.5.1, 7.6.0-7.8.0, 8.0.1

Oracle Construction and Engineering Executive Summary

This Critical Security Patch Update contains 1 new security patch for Oracle Construction and Engineering.  This vulnerability is not remotely exploitable without authentication, i.e., may not be exploited over a network without requiring user credentials. 

The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Construction and Engineering is 6.5.

The Oracle Construction and Engineering products and versions affected by vulnerabilities that are addressed in this Critical Security Patch Update are:

  • Primavera P6 Enterprise Project Portfolio Management, versions 21.12.0.0-21.12.21.8, 22.12.0.0-22.12.21.3, 23.12.0-23.12.19, 24.12.0-24.12.15, 25.12.0-25.12.6

Oracle E-Business Suite Executive Summary

This Critical Security Patch Update contains 126 new security patches for Oracle E-Business Suite.  33 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. 

The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle E-Business Suite is 9.8.

The Oracle E-Business Suite products and versions affected by vulnerabilities that are addressed in this Critical Security Patch Update are:

  • Oracle E-Business Suite, versions 12.2.3-12.3.15

Oracle Enterprise Manager Executive Summary

This Critical Security Patch Update contains 11 new security patches for Oracle Enterprise Manager.  5 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  None of these patches are applicable to client-only installations, i.e., installations that do not have Oracle Enterprise Manager installed.

The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Enterprise Manager is 9.1.

The Oracle Enterprise Manager products and versions affected by vulnerabilities that are addressed in this Critical Security Patch Update are:

  • Oracle Enterprise Manager Base Platform, versions 13.5, 24.1
  • Oracle Enterprise Manager for Systems Infrastructure, versions 13.5, 24.1

Oracle Financial Services Applications Executive Summary

This Critical Security Patch Update contains 7 new security patches for Oracle Financial Services Applications.  5 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. 

The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Financial Services Applications is 9.1.

The Oracle Financial Services Applications products and versions affected by vulnerabilities that are addressed in this Critical Security Patch Update are:

  • Oracle Financial Services Behavior Detection Platform, versions 8.0.8.1, 8.1.2.11
  • Oracle Financial Services Enterprise Case Management, versions 8.0.8.2, 8.1.2.11
  • Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition, version 8.0.8.0

Oracle Food and Beverage Applications Executive Summary

This Critical Security Patch Update contains 2 new security patches for Oracle Food and Beverage Applications.  Both of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. 

The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Food and Beverage Applications is 9.1.

The Oracle Food and Beverage Applications products and versions affected by vulnerabilities that are addressed in this Critical Security Patch Update are:

  • Oracle Hospitality Simphony, versions 19.8-19.8.5, 19.9-19.9.3, 19.10-19.10.1

Oracle Fusion Middleware Executive Summary

This Critical Security Patch Update contains 262 new security patches for Oracle Fusion Middleware.  182 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. 

The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Fusion Middleware is 10.0.

The Oracle Fusion Middleware products and versions affected by vulnerabilities that are addressed in this Critical Security Patch Update are:

  • Helidon, versions 1.4.19, 1.4.20, 3.2.18, 3.2.19, 3.2.20, 4.5.0, 4.5.1, 4.5.3
  • Oracle Access Manager, versions 12.2.1.4.0, 14.1.2.1.0
  • Oracle Identity Manager, versions 12.2.1.4.0, 14.1.2.1.0
  • Oracle Identity Manager Connector, versions 12.2.1.4.0, 14.1.2.1.0
  • Oracle Internet Directory, versions 12.2.1.4.0, 14.1.2.1.0
  • Oracle Managed File Transfer, versions 12.2.1.4.0, 14.1.2.0.0
  • Oracle Outside In Technology, version 8.5.8
  • Oracle Reports Developer, versions 12.2.1.19.0, 14.1.2.0.0
  • Oracle SOA Suite, versions 12.2.1.4.0, 14.1.2.0.0
  • Oracle Unified Directory, versions 12.2.1.4.0, 14.1.2.1.0
  • Oracle Virtual Directory, versions 12.2.1.4.0, 14.1.2.0.0
  • Oracle Web Services Manager, versions 12.2.1.4.0, 14.1.2.0.0
  • Oracle WebCenter Content, versions 12.2.1.4.0, 14.1.2.0.0
  • Oracle WebCenter Enterprise Capture, versions 12.2.1.4.0, 14.1.2.0.0
  • Oracle WebCenter Portal, versions 12.2.1.4.0, 14.1.2.0.0
  • Oracle WebCenter Sites, versions 12.2.1.4.0, 14.1.2.0.0
  • Oracle WebLogic Server, versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
  • Service Delivery Platform, version 14.1.2.0.0

Oracle Analytics Executive Summary

This Critical Security Patch Update contains 16 new security patches for Oracle Analytics.  3 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. 

The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Analytics is 9.9.

The Oracle Analytics products and versions affected by vulnerabilities that are addressed in this Critical Security Patch Update are:

  • Oracle BI Publisher, versions 8.2.0.0.0, 12.2.1.4.0, 26.1.0.0.0
  • Oracle Business Intelligence Enterprise Edition, versions 8.2.0.0.0, 12.2.1.4.0, 26.1.0.0.0

Oracle Hospitality Applications Executive Summary

This Critical Security Patch Update contains 1 new security patch for Oracle Hospitality Applications.  This vulnerability is remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. 

The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Hospitality Applications is 8.8.

The Oracle Hospitality Applications products and versions affected by vulnerabilities that are addressed in this Critical Security Patch Update are:

  • Oracle Hospitality OPERA 5 Property Services, versions 5.6.28.0-5.6.28.1

Oracle Hyperion Executive Summary

This Critical Security Patch Update contains 262 new security patches for Oracle Hyperion.  107 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. 

The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Hyperion is 10.0.

The Oracle Hyperion products and versions affected by vulnerabilities that are addressed in this Critical Security Patch Update are:

  • Oracle Hyperion Calculation Manager, version 11.2.25.0.0
  • Oracle Hyperion Data Relationship Management, versions 11.2.23.0.0, 11.2.25.0.0
  • Oracle Hyperion Financial Management, version 11.2.25.0.0
  • Oracle Hyperion Financial Reporting, version 11.2.25.0.0
  • Oracle Hyperion Infrastructure Technology, version 11.2.25.0.0
  • Oracle Hyperion Profitability and Cost Management, version 11.2.25.0.0

Oracle Java SE Executive Summary

This Critical Security Patch Update contains 4 new security patches for Oracle Java SE.  All of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. 

The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Java SE is 7.5.

The Oracle Java SE products and versions affected by vulnerabilities that are addressed in this Critical Security Patch Update are:

  • Oracle GraalVM Enterprise Edition, version 21.3.19
  • Oracle GraalVM for JDK, versions 17.0.20, 21.0.12
  • Oracle Java SE, versions 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2

Oracle JD Edwards Executive Summary

This Critical Security Patch Update contains 6 new security patches for Oracle JD Edwards.  2 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. 

The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle JD Edwards is 9.8.

The Oracle JD Edwards products and versions affected by vulnerabilities that are addressed in this Critical Security Patch Update are:

  • JD Edwards EnterpriseOne Orchestrator, versions 9.2.0.0-9.2.26.4
  • JD Edwards EnterpriseOne Tools, versions 9.2.0.0-9.2.26.4
  • JD Edwards EnterpriseOne US Payroll, version 9.2

Oracle MySQL Executive Summary

This Critical Security Patch Update contains 6 new security patches for Oracle MySQL.  5 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. 

The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle MySQL is 8.2.

The Oracle MySQL products and versions affected by vulnerabilities that are addressed in this Critical Security Patch Update are:

  • MySQL AI, versions 9.7.0-9.7.2, 26.7.0
  • MySQL Cluster, versions 8.0.0-8.0.48, 8.4.0-8.4.11, 9.7.0-9.7.2
  • MySQL Shell, versions 8.4.0-8.4.11, 9.7.0-9.7.2, 26.7.0

Oracle PeopleSoft Executive Summary

This Critical Security Patch Update contains 15 new security patches for Oracle PeopleSoft.  7 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. 

The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle PeopleSoft is 9.8.

The Oracle PeopleSoft products and versions affected by vulnerabilities that are addressed in this Critical Security Patch Update are:

  • PeopleSoft Enterprise CC Common Application Objects, version 9.2
  • PeopleSoft Enterprise FIN Common Objects, version 9.2
  • PeopleSoft Enterprise FIN Common Objects Brazil, version 9.1
  • PeopleSoft Enterprise FIN Lease Administration, version 9.2
  • PeopleSoft Enterprise PeopleTools, versions 8.61-8.63

Oracle Retail Applications Executive Summary

This Critical Security Patch Update contains 5 new security patches for Oracle Retail Applications.  All of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. 

The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Retail Applications is 7.5.

The Oracle Retail Applications products and versions affected by vulnerabilities that are addressed in this Critical Security Patch Update are:

  • Oracle Retail Advanced Inventory Planning, versions 15.0, 16.0
  • Oracle Retail Assortment Planning, versions 15.0, 16.0
  • Oracle Retail Fiscal Management, version 14.2
  • Oracle Retail Item Planning, versions 15.0, 16.0
  • Oracle Retail Regular Price Optimization, versions 15.0, 16.0

Oracle Siebel CRM Executive Summary

This Critical Security Patch Update contains 50 new security patches for Oracle Siebel CRM.  21 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. 

The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Siebel CRM is 9.9.

The Oracle Siebel CRM products and versions affected by vulnerabilities that are addressed in this Critical Security Patch Update are:

  • Siebel Applications, versions 17.0-26.6

Oracle Supply Chain Executive Summary

This Critical Security Patch Update contains 48 new security patches for Oracle Supply Chain.  19 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. 

The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Supply Chain is 9.8.

The Oracle Supply Chain products and versions affected by vulnerabilities that are addressed in this Critical Security Patch Update are:

  • Oracle Agile Engineering Data Management, version 6.2.1
  • Oracle Agile PLM, version 9.3.6
  • Oracle Agile PLM MCAD Connector, version 3.6
  • Oracle Demand Planning, versions 12.1, 12.2
  • Oracle Product Lifecycle Analytics, version 3.6.1

Oracle Virtualization Executive Summary

This Critical Security Patch Update contains 21 new security patches for Oracle Virtualization.  2 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. 

The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Virtualization is 8.2.

The Oracle Virtualization products and versions affected by vulnerabilities that are addressed in this Critical Security Patch Update are:

  • Oracle VM VirtualBox, version 7.2.14