Oracle May 2026 CSPU Release Intelligence
Oracle's first monthly Critical Security Patch Update — 37 security advisories across 37 Oracle products. Covers Oracle Fusion Cloud + the broader Oracle portfolio (Database, Java SE, MySQL, EBS, PeopleSoft, JD Edwards, Siebel, Middleware, Hyperion, GoldenGate and more).
About the Oracle May 2026 CSPU
On May 28, 2026, Oracle launched the first monthly Critical Security Patch Update (CSPU) — establishing a new monthly cadence that complements the existing quarterly Critical Patch Update (CPU). This release contains 37 security advisories spanning 37 Oracle products: 9 affecting Oracle Fusion Cloud directly and 28 covering the broader Oracle stack (Database, Java SE, MySQL, EBS, PeopleSoft, JD Edwards, Siebel, Middleware, Analytics, Hyperion, etc.).
Customers using Oracle-managed cloud services receive these updates automatically. Customer-managed environments — including on-premise installations, hybrid landscapes, and customer-patched Oracle products — must apply the May 2026 CSPU manually and validate critical business flows after patching.
Fusion Cloud Security Changes
9 security advisories affecting Oracle Fusion Cloud modules — Identity, Integration, Automation Framework, and core ERP modules.
Monthly Critical Security Patch Updates (CSPU) Introduction
What changed: Oracle introduces monthly CSPUs for critical vulnerabilities between quarterly CPUs
Why it matters: Monthly security cadence increases frequency of regression/security validation requirements
Security Hardening for AP Transactions
What changed: Security fixes may impact invoice processing, approvals, and integrations
Why it matters: Security patches can impact invoice workflows and approval routing
Payment Security Controls
What changed: Payment and banking security fixes likely included in CSPUs
Why it matters: Payment interfaces are highly sensitive to security patches
Supplier & Procurement Access Security
What changed: Procurement role/access vulnerabilities may be patched
Why it matters: Procurement integrations often rely on role-based access
AR Security & Integration Updates
What changed: CSPUs may include fixes affecting customer transactions and AR integrations
Why it matters: AR APIs and imports are commonly impacted by security changes
GL Access & Posting Security
What changed: Security fixes may impact posting privileges and accounting access
Why it matters: GL security impacts financial control compliance
OAuth / SSO / API Security Enhancements
What changed: Oracle highlights accelerated vulnerability remediation and AI-assisted detection
Why it matters: Authentication failures are common after security updates
Selenium / UI Automation Stability
What changed: Security updates may alter page DOM, headers, redirects, and session handling
Why it matters: Frequent CSPUs increase automation maintenance effort
AI-Accelerated Vulnerability Detection
What changed: Oracle using AI models to improve vulnerability detection and remediation cadence
Why it matters: Faster security remediation means more frequent enterprise validation cycles
Oracle Stack Security Advisories
28 security advisories covering Oracle products beyond Fusion Cloud — Database, Java SE, MySQL, Middleware, EBS, PeopleSoft, JD Edwards, Siebel, Analytics, Hyperion, GoldenGate and more.
Monthly critical security readiness
What changed: Validate telecom platform after targeted CSPU
Banking security readiness
What changed: Validate banking apps and batch controls
Middleware hardening
What changed: Validate WebLogic/OAM/SSO stack
Database security readiness
What changed: Validate DB and connector compatibility
PeopleSoft ERP readiness
What changed: Validate roles, pages, batch jobs
EBS security readiness
What changed: Validate responsibilities and concurrent jobs
BI security readiness
What changed: Validate dashboards, reports, schedules
Retail security readiness
What changed: Validate POS/order/inventory flows
CRM security readiness
What changed: Validate CRM object access and APIs
Java runtime patching
What changed: Validate Java-dependent workloads
Replication security readiness
What changed: Validate replication and CDC
Monitoring platform readiness
What changed: Validate agents and targets
Virtualization security readiness
What changed: Validate VM hosts and migrations
Database server readiness
What changed: Validate DB patch and app connectivity
Utility app readiness
What changed: Validate metering/billing flows
Planning security readiness
What changed: Validate Essbase/planning workloads
Project app readiness
What changed: Validate project/contract workflows
Compliance app readiness
What changed: Validate clinical/compliance workflows
SCM readiness
What changed: Validate inventory/order flows
Blockchain readiness
What changed: Validate node/API operations
Commerce readiness
What changed: Validate storefront/checkout APIs
JDE readiness
What changed: Validate roles and UBEs
RDF integration readiness
What changed: Validate RDF repositories/APIs
AHF readiness
What changed: Validate diagnostics and telemetry
ORDS readiness
What changed: Validate REST endpoints and auth
Engineered systems readiness
What changed: Validate system firmware/infra stack
TimesTen readiness
What changed: Validate cache and sync workloads
Hospitality readiness
What changed: Validate reservations/POS flows
Affected Components Across May 2026 CSPU
Deduplicated inventory of components impacted by the May 2026 CSPU. Use these as your regression scope baseline.
Affected Pages
43Affected APIs
9Affected ESS Jobs
10Affected Config Objects
17Affected Business Processes
11Recommended Test Cases
28May 2026 CSPU Readiness Checklist
Tick these off before applying to production.
May 2026 CSPU FAQs
Common questions about Oracle's first monthly CSPU release.
What is the Oracle May 2026 CSPU?
Which Oracle products does the May 2026 CSPU cover?
What's the severity breakdown for May 2026 CSPU?
Are Oracle Cloud customers affected by May 2026 CSPU?
What should we validate after applying May 2026 CSPU?
When is the next CSPU after May 2026?
Validate the May 2026 CSPU Across Your Oracle Stack
Tenant-specific May 2026 CSPU impact analysis with auto-composed security regression test packs — covering Fusion Cloud and the broader Oracle product portfolio.