{"id":8848,"date":"2026-07-22T18:14:27","date_gmt":"2026-07-22T18:14:27","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=8848"},"modified":"2026-07-22T18:14:27","modified_gmt":"2026-07-22T18:14:27","slug":"oracles-july-update-fixes-ten-10-0-vulnerabilities-in-fusion-middleware","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=8848","title":{"rendered":"Oracle\u2019s July update fixes ten 10.0 vulnerabilities in Fusion Middleware"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Oracle\u2019s July 2026 Critical Patch Update, its largest ever, contains 1,449 new security patches spanning 32 product families, from Oracle Database and E-Business Suite to PeopleSoft, GoldenGate, Java SE, and Fusion Middleware.<\/p>\n<p class=\"wp-block-paragraph\">Fusion Middleware was particularly hard hit, with new security patches for 355 security vulnerabilities, 219 of them remotely exploitable without authentication, meaning they can be exploited over a network without requiring user credentials. Ten of them scored a \u201cperfect\u201d 10.0 on the Common Vulnerability Scoring System (CVSS).<\/p>\n<p class=\"wp-block-paragraph\">These included easily exploitable vulnerabilities allowing unauthenticated attackers with network access via HTTP to compromise Oracle Data Integrator, Oracle Access Manager, Oracle HTTP Server, Oracle Platform Security for Java, Oracle WebCenter Content, Service Delivery Platform, or Oracle Weblogic Server Proxy Plug-in,<\/p>\n<p class=\"wp-block-paragraph\">No other products were found to have quite such extreme vulnerabilities, but there were plenty of others scoring almost as badly.<\/p>\n<h2 class=\"wp-block-heading\">Two critical flaws in Oracle Database Server<\/h2>\n<p class=\"wp-block-paragraph\">The most severe flaw Oracle patched in its flagship database product is CVE-2026-61211, a vulnerability in the RDBMS component\u2019s DBMS_CLOUD package with a CVSS score of 9.9.<\/p>\n<p class=\"wp-block-paragraph\">This easily exploitable vulnerability allows a low-privileged attacker having Execute DBMS_CLOUD privilege with network access via Oracle Net to compromise the RDBMS, <a href=\"https:\/\/www.oracle.com\/security-alerts\/cpujul2026verbose.html\">Oracle said in the patch update statement<\/a>. \u201cWhile the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of RDBMS,\u201d it warned.<\/p>\n<p class=\"wp-block-paragraph\">The flaw affects Database Server versions 19.3 through 19.31 and 23.4.0 through 23.26.2.<\/p>\n<p class=\"wp-block-paragraph\">Sanchit Vir Gogia, chief analyst at Greyhound Research, said the 9.9 score should be read as serious but conditional. Exposure depends on configuration, he said: On customer-managed databases, DBMS_CLOUD is absent until installed, and grants and network access lists determine the radius from there. \u201cWhere DBMS_CLOUD is broadly granted and reachable, the emergency is real and the window is seventy-two hours; where it is absent, the accelerated database wave will do.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Vibhum Dubey, a cybersecurity researcher and red teamer, said the flaw stood out to him because it checks several boxes that concern defenders.<\/p>\n<p class=\"wp-block-paragraph\">\u201cDatabase servers often hold an organization\u2019s most valuable data, so even if exploitation is not publicly observed yet, I don\u2019t think this is the kind of issue you leave until the next routine maintenance window if your environment is exposed,\u201d Dubey said.<\/p>\n<p class=\"wp-block-paragraph\">A second Database Server flaw, CVE-2026-47040, affects Connection Manager in Oracle Net Services, is remotely exploitable without credentials. Oracle\u2019s risk matrix lists six Database Product vulnerabilities in this cycle as reachable over a network with no authentication required, the statement added.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-7383, an OpenSSL-related TLS vulnerability, affects two products, Database Server and Autonomous Health Framework, since both bundle the same third-party component. Oracle\u2019s advisory notes the Database Server patch for that CVE also resolves 19 related OpenSSL CVEs bundled into the same fix.<\/p>\n<p class=\"wp-block-paragraph\">Oracle GoldenGate received 27 new patches, nine of which do not require authentication to exploit, including CVE-2026-2332, a flaw in the Big Data and Application Adapters component tied to Eclipse Jetty, the statement added.<\/p>\n<p class=\"wp-block-paragraph\">There were also two critical flaws in Oracle\u2019s TimesTen in-memory database.<\/p>\n<p class=\"wp-block-paragraph\">The remainder of the release spans E-Business Suite, WebLogic Server, PeopleSoft, Siebel, JD Edwards, Communications, Retail Applications, Utilities Applications, MySQL, Solaris and VM VirtualBox.<\/p>\n<h2 class=\"wp-block-heading\">Volume repair<\/h2>\n<p class=\"wp-block-paragraph\">Gogia said the volume itself marks a shift.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAt 1,449 patches, against 481 in April 2026 and 309 a year earlier, patch load has outgrown the queue built to hold it,\u201d he said. He recommended a tiered response: \u201cThe reachable and the reported inside seventy-two hours, the trusted core inside ten days, the rest by risk before the October release.\u201d<\/p>\n<p class=\"wp-block-paragraph\">He also flagged a specific risk in how organizations might triage E-Business Suite. \u201cOracle\u2019s advisory concedes that E-Business Suite exposure sits partly in underlying Database and Fusion Middleware versions outside the E-Business Suite matrix. The fastest way to mis-prioritise this release is to patch by product logo instead of trust boundary.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Third Tuesday, quarterly cycle<\/h2>\n<p class=\"wp-block-paragraph\">The July release is the third quarterly Critical Patch Update of 2026, and the first since the <a href=\"https:\/\/www.csoonline.com\/article\/4179473\/oracles-first-monthly-patch-release-fixes-35-flaws-including-11-rated-critical.html\">introduction in May<\/a> of the monthly Critical Security Patch Update program.<\/p>\n<p class=\"wp-block-paragraph\">Gogia said Oracle has effectively layered a second cadence on top of the existing one rather than replacing it.<\/p>\n<p class=\"wp-block-paragraph\">\u201cQuarterly Critical Patch Updates remain and stay cumulative; monthly Critical Security Patch Updates now sit on top,\u201d he said, adding that enterprise adoption of the new rhythm remains low because of \u201ccertification obligations, regression exposure and scarce specialist hours.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Dubey made a similar point about organizational readiness: \u201cIn large enterprises, patching is rarely a technical problem. It is an operational one. Database administrators, application owners, infrastructure teams, business stakeholders, and change advisory boards all have to align.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Niyati Daftary, principal analyst at Gartner, said the release underscores a broader shift in how patching is approached.<\/p>\n<p class=\"wp-block-paragraph\">\u201cPatching is no longer a race to remediate every vulnerability. It is a discipline of identifying the exposures that matter most and reducing business risk as efficiently as possible,\u201d she said, adding that organizations should prioritize based on exposure, business impact and exploitability, starting with internet-facing assets and mission-critical systems.<\/p>\n<p class=\"wp-block-paragraph\">Daftary pointed to continuous threat exposure management and adversarial exposure validation as increasingly relevant frameworks, since CVSS scores \u201cmeasure theoretical severity rather than actual enterprise risk.\u201d Patching alone will not be sufficient, Daftary said, and organizations should continue investing in defense in depth, including behavioral threat detection and incident response.<\/p>\n<p class=\"wp-block-paragraph\">Oracle\u2019s next cumulative Critical Patch Update will come on Oct. 20, 2026, with smaller Critical Security Patch Updates on Aug. 18 and Sept. 15.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Oracle\u2019s July 2026 Critical Patch Update, its largest ever, contains 1,449 new security patches spanning 32 product families, from Oracle Database and E-Business Suite to PeopleSoft, GoldenGate, Java SE, and Fusion Middleware. Fusion Middleware was particularly hard hit, with new security patches for 355 security vulnerabilities, 219 of them remotely exploitable without authentication, meaning they [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":8849,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-8848","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8848"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8848"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8848\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/8849"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8848"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8848"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8848"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}