Oracle July 2026 CPU Release Intelligence
1,449 security updates covering 1,235 unique CVEs across 32 Oracle product families — roughly three times the size of the April 2026 CPU. Oracle E-Business Suite alone accounts for 410 patches, the largest single-product total we have recorded.
July 2026 CPU at a Glance
Oracle's July 2026 Critical Patch Update, released on 21 July 2026, is the largest CPU Oracle has published — 1,449 security updates addressing 1,235 unique CVEs across 32 product families. For context, the April 2026 CPU contained 481 patches across 28 families. The volume increase alone changes the regression testing calculus for most Oracle estates.
Three shifts that matter for ERP teams
Roughly 3× the April CPU
1,449 updates against April's 481. If your patch testing window was sized against a typical quarter, it is now undersized. The practical risk is not that teams skip the patch — it is that they apply it with a regression pass scoped for a much smaller release.
410 patches — 28% of the CPU
EBS is the single most-patched family this quarter, ahead of Fusion Middleware. For EBS customers this is a full-estate regression event, not a targeted fix. 45 of the EBS vulnerabilities are remotely exploitable without authentication.
Concentrated in middleware
Fusion Middleware carries 219 remotely exploitable, unauthenticated vulnerabilities out of 355 patches — the highest concentration in the CPU. Communications follows with 122 of 168. Internet-facing middleware is the priority tier.
Where the July 2026 patches landed
Patch counts and unauthenticated remote-exploit counts for the product families most relevant to Oracle ERP and HCM estates. Percentages are share of the 1,449 total security updates.
| Product family | Patches | Share of CPU | Remote / unauth | Testing implication |
|---|---|---|---|---|
| Oracle E-Business Suite | 410 | 28.3% | 45 | Full-estate regression. Forms, OAF pages, concurrent programs, interfaces. |
| Oracle Fusion Middleware | 355 | 24.5% | 219 | Highest unauthenticated exposure. WebLogic, Access Manager, Coherence, BI Publisher. |
| Oracle Communications | 168 | 11.6% | 122 | Cloud Native Core platforms; prioritise internet-facing nodes. |
| Oracle PeopleSoft | 84 | 5.8% | 45 | Self-service flows, PIA, Integration Broker, role security. |
| Oracle MySQL | 54 | 3.7% | 9 | Server, Cluster, Router and Connectors. |
| Supply Chain | 39 | 2.7% | 16 | Planning and logistics integrations. |
| Financial Services Applications | 31 | 2.1% | 26 | 84% unauthenticated — disproportionate exposure for the patch count. |
| Retail Applications | 22 | 1.5% | 20 | 91% unauthenticated — the highest ratio in the CPU. |
| JD Edwards | 20 | 1.4% | 4 | EnterpriseOne tools and web runtime. |
| Oracle Database Server | 15 | 1.0% | 6 | 19c, 21c and 23c. Low count, high blast radius. |
Figures compiled from Oracle's Critical Patch Update Advisory for July 2026 and Tenable's analysis of the release, verified 22 July 2026. The families listed above account for approximately 1,198 of the 1,449 updates; the balance is spread across the remaining 22 product families. Always confirm the affected version ranges for your own estate against Oracle's advisory before planning.
A four-tier approach to a 1,449-patch CPU
No enterprise regression-tests 1,449 patches uniformly. The question is which subset genuinely changes behaviour in your configuration, and which merely needs a smoke test.
Internet-facing, unauthenticated, exploitable
Fusion Middleware (219 unauthenticated) and Communications (122) first, then any Retail or Financial Services component exposed beyond the perimeter. These need patching on the security team's clock, not the release calendar's. Regression here is about confirming the patch did not break authentication and integration paths, not about exhaustive functional coverage.
E-Business Suite's 410 patches
Volume, not severity, is the challenge. A patch set this broad touches forms, OAF pages, concurrent programs and interfaces across most modules. The efficient path is impact analysis first — determine which of your customisations, personalisations and integrations sit on changed objects — then scope regression to that intersection rather than to the whole module list.
PeopleSoft, JD Edwards, Supply Chain
Meaningful counts with lower unauthenticated exposure. These fit a normal patch window with a targeted regression pass over self-service flows, role security, integration broker traffic and the transactional paths your business actually runs at month end.
Database Server and MySQL
15 Database Server patches is a small number attached to a very large blast radius. Low patch counts invite deferral; the correct response is a short, high-confidence validation of query behaviour, performance baselines and application connectivity rather than a long regression cycle.
What to test after applying the July 2026 CPU
Security patches rarely change business logic deliberately, but they frequently change authentication, session handling, serialisation and integration behaviour. That is where post-CPU defects concentrate.
- →Authentication and SSO — login, session timeout, token refresh, SAML/OAuth assertion handling. The most common source of post-patch incidents.
- →Role and responsibility security — confirm no privilege drift after security-model patches, particularly in EBS and PeopleSoft.
- →Integration payloads — REST and SOAP contracts, serialisation formats, certificate and TLS negotiation with downstream systems.
- →Core transactional flows — procure-to-pay, order-to-cash, record-to-report end-to-end, including approvals and workflow routing.
- →Customisations and personalisations — anything sitting on a patched standard object is the highest-probability breakage.
- →Reporting and BI — BI Publisher templates and scheduled output, given the Fusion Middleware patch volume.
How SyntraFlow helps
SyntraFlow is built for exactly this problem — turning a large Oracle patch drop into a scoped, defensible regression plan instead of a guess.
Identify which of your customisations, personalisations, interfaces and reports intersect the patched objects — so regression scope is derived, not estimated.
Assemble a targeted test pack for the affected modules and flows rather than re-running an entire suite that was never sized for a 1,449-patch release.
Run the highest-risk paths first so that a go/no-go decision is possible early in the window rather than at the end of it.
July 2026 CPU questions
What is in the Oracle July 2026 Critical Patch Update?
Released on 21 July 2026, the July 2026 CPU contains 1,449 security updates addressing 1,235 unique CVEs across 32 Oracle product families. 261 of the issues are rated critical severity, representing about 18% of the release, with high severity at 52.7% and medium at 24.7%.
Why is this CPU so much larger than April 2026?
The April 2026 CPU contained 481 patches across 28 product families; July 2026 contains 1,449 across 32 — roughly three times the volume. The largest single contributor is Oracle E-Business Suite at 410 patches, up from a far smaller April figure. Teams should treat their standard patch testing window as undersized for this quarter.
Which Oracle products received the most patches in July 2026?
Oracle E-Business Suite led with 410 patches (28.3% of the release), followed by Fusion Middleware with 355, Communications with 168, PeopleSoft with 84 and MySQL with 54. Supply Chain received 39, Financial Services Applications 31, Retail Applications 22, JD Edwards 20 and Database Server 15.
Which July 2026 vulnerabilities are remotely exploitable without authentication?
Unauthenticated remote exposure is concentrated in Fusion Middleware, with 219 of its 355 patches falling into that category, followed by Communications with 122 of 168. Proportionally, Retail Applications (20 of 22) and Financial Services Applications (26 of 31) carry the highest ratios. Oracle E-Business Suite has 45 unauthenticated remote issues among its 410 patches.
What should Oracle E-Business Suite customers do first?
Treat it as a full-estate regression event rather than a targeted fix. With 410 patches, the efficient approach is impact analysis first — establish which customisations, personalisations, interfaces and reports sit on patched objects — then scope regression to that intersection. Address the 45 unauthenticated remote issues on the security team's timeline in parallel.
What testing is needed after applying the July 2026 CPU?
Prioritise authentication and SSO flows, role and responsibility security, integration payloads and contracts, core transactional paths such as procure-to-pay and order-to-cash, and any customisation sitting on a patched standard object. Security patches rarely change business logic on purpose, but they frequently change authentication, session handling and serialisation behaviour — which is where post-CPU defects concentrate.
Where can I find Oracle's official July 2026 advisory?
Oracle publishes the full advisory, including affected version ranges and individual CVE detail, at oracle.com/security-alerts/cpujul2026.html. Always confirm the affected versions for your own estate against Oracle's advisory before planning a patch window — the figures on this page are a planning summary, not a substitute for the advisory itself.
Related release intelligence
481 patches across 28 product families — the comparison baseline for this quarter.
How to structure a repeatable regression cycle around Oracle's patch cadence.
Every Oracle CPU and security alert we track, with impact analysis for each.
1,449 patches. One regression window.
See how SyntraFlow scopes a July 2026 CPU regression plan against your own Oracle configuration — so you test what actually changed.
Book a July CPU impact review