back to top

Trending Content:

Oracle Simply Shipped 1,449 Safety Patches in One Quarter. We Checked How A lot of It Is Really New. | Cybersecurity

‍Oracle’s July 2026 Vital Patch Replace is almost thrice bigger than any launch within the firm’s historical past. We parsed all 23 of Oracle’s quarterly advisories since 2021, joined them towards the official CVE report, and benchmarked eight peer distributors to reply three questions: how a lot of that is genuinely new, does it actually mirror AI-accelerated patching, and the way distinctive is it?

TL;DRThe July 2026 CPU is a real outlier, not a counting trick. 1,449 safety patches — 3.7x Oracle’s 2021–2025 quarterly common, and a pair of.8x the earlier all-time report (520 patches, April 2022).It is not a rollup of the brand new month-to-month updates. Only one.8% of July’s CVEs had already shipped in Oracle’s Could/June month-to-month patches.It is not the same old third-party open-source sweep, both. Traditionally about two-thirds of an Oracle CPU patches third-party CVEs. July inverted that: 77% are Oracle’s personal CVEs — 1,110 of them, towards a historic norm of ~102 per quarter.The issues are new to the general public report, and so they did not come from outdoors. The median July CVE was reserved (the date a CVE ID is created, earlier than any particulars are public) simply 13 days earlier than the patch shipped, and exterior researchers are credited on no extra CVEs than in a traditional quarter. The wave is internally sourced.The timing traces up with Oracle’s AI claims. In late April 2026 Oracle introduced it’s “using AI, including frontier models, to improve how issues are found and to accelerate how fixes are delivered”. Oracle’s own-CVE output was flat for 5 years, then jumped an order of magnitude within the first full quarter after that announcement. The correlation is robust; impartial verification would not exist but.The {industry} is surging too — however not like this. Microsoft, Adobe, Pink Hat, and VMware all exceeded 1.5x their very own CVE baselines in 2026; SAP, Cisco, IBM, and Apple didn’t. No peer is close to 10x.For third-party threat groups: in case your distributors run E-Enterprise Suite, PeopleSoft, or WebLogic, how shortly they take up a 1,449-patch quarter is now a significant, measurable threat sign — and quarters this dimension often is the new regular.A report by any depend

On July 21, 2026, Oracle launched its quarterly Vital Patch Replace (CPU) with a headline quantity that made even patch-fatigued directors look twice: 1,449 new safety patches throughout 32 product households.

Relying on who’s counting, you may see totally different totals — 1,235 from Tenable, 1,449 from Oracle, or figures as much as 1,461. They’re all describing the identical launch. Our parse of the advisory reconciles them:

‍1,235 Distinctive CVEs in Oracle’s major risk-matrix rows (Tenable’s methodology)‍1,449 Oracle’s headline: distinct safety patches‍1,461 All distinctive CVEs, together with “the patch for X also addresses Y” notes and bundled third-party fixes

Two denominators seem all through this evaluation, so we’ll repair them now: percentages of the entire launch use the 1,461 distinctive CVEs; attribution percentages (who assigned the CVE) use the 1,449 CVEs that matched a report within the official CVE Record (12 of the 1,461 hadn’t propagated to the CVE report at time of study — and sure, 1,449 matched CVEs equaling 1,449 patches is pure coincidence; they’re various things).

Whichever depend you favor, the historic comparability is unambiguous. Until famous in any other case, each baseline on this piece is the 2021–2025 interval — the 20 quarterly CPUs earlier than the present yr. Over that window Oracle averaged 390 patches per quarter, by no means exceeding 520, and 2026’s personal January and April CPUs (337 and 481) stayed inside it. July 2026 is 3.7x that common and a pair of.8x the all-time report — and the report it broke (April 2022) was itself inflated by an industry-wide emergency, the Spring4Shell sweep.

Oracle safety patches per quarterly CPU, 2021–2026

So the amount is actual. The extra attention-grabbing query is what’s in it.

4 deflationary explanations, examined

When a vendor’s patch depend triples, the seasoned response is skepticism: large numbers often imply bundling, double-counting, or housekeeping. We examined the 4 most believable deflationary explanations towards the information. Three fail outright. The fourth deserves extra honesty than it often will get.

Speculation 1: It is simply the brand new month-to-month patches rolled up. — Rejected. In Could 2026 Oracle started transport month-to-month Vital Safety Patch Updates (CSPUs) between quarterly CPUs — 77 patches in Could, 245 in June. July is the primary quarterly CPU launched below the brand new cadence, so maybe ~320 of its patches are merely the monthlies restated. They don’t seem to be. We extracted each CVE from the Could and June CSPU advisories and matched them towards July: solely 27 of the CPU’s 1,461 CVEs (1.8%) had appeared in a month-to-month replace. The monthlies and the quarterly are virtually solely disjoint — which additionally means Oracle’s complete 2026 output is even bigger than the CPU alone suggests.

Speculation 2: It is a third-party open-source sweep. — Rejected. That is the same old anatomy of an enormous Oracle CPU. Oracle merchandise bundle huge quantities of open-source software program, and quarterly CPUs sweep in months of Apache, OpenSSL, and Linux-ecosystem CVEs. In April 2026, Qualys discovered 78% of CPU patches had been for non-Oracle CVEs; our personal information places that quarter at 75.8%, and the 2021–2025 common at 66.8%. If July had been extra of the identical, the “new Oracle security work” can be a fraction of the headline. As a substitute, July inverts the ratio: becoming a member of each CVE towards the official CVE Record v5 report reveals 76.6% (1,110 of the 1,449 matched CVEs) had been assigned by Oracle’s personal CVE Numbering Authority (CNA) — vulnerabilities in Oracle’s personal code, disclosed by way of Oracle’s personal course of. The third-party the rest (339 CVEs) is led by GitHub-assigned open-source CVEs (91), Apache (59), and VMware (31), with the remaining scattered throughout dozens of smaller CNAs — a small fraction by comparability.

Speculation 3: It is re-listing outdated CVEs throughout product traces. — Rejected. Oracle counts a CVE as soon as per affected product line, and quarterly advisories routinely re-list CVEs from prior quarters. Traditionally solely 63.4% of the CVEs in a given CPU seem in an Oracle advisory for the primary time. In July 2026, 91.9% are first-ever appearances — the best share of any quarter we measured. And solely 5.2% of July’s CVEs had been greater than a yr outdated at patch time, versus a 2021–2025 common of 24.0%. This isn’t debt paydown.

Speculation 4: It is a disclosure-policy change, not a discovery breakthrough. — Can’t be excluded. That is the strongest skeptical studying, and our information can’t rule it out. Distributors repair internally found bugs with out assigning CVEs extra usually than anybody admits; if Oracle merely began CVE-ing flaws it beforehand fastened silently (as Microsoft started doing for cloud vulnerabilities in 2024), the CVE depend would explode with no change in underlying discovery. Critically, the freshness metrics above are equally per this studying — an internally discovered bug will get its CVE reserved at patch time whether or not it was discovered final month or final yr. What we will say: we discover no introduced change to Oracle’s CVE coverage (Oracle’s CPU documentation has lengthy said that CPUs embody fixes for internally discovered points), no analyst has recognized one, and Oracle’s personal clarification attributes the change to discovery (“how issues are found”), not disclosure. The 2 explanations are additionally not mutually unique — AI-assisted triage may very well be precisely what made mass CVE task for inside finds possible. (One factor the credit score information settles both approach: the wave got here from inside Oracle, not from a surge in exterior reviews — see the anatomy part.) The defensible conclusion, and the one this evaluation stands on, is about disclosure: Oracle is now disclosing and fixing safety flaws in its personal code at roughly ten occasions its historic price. Whether or not the discovering or the telling modified — Oracle says the discovering — is the one query solely Oracle can reply.

6a6025e87ca30559928e8d10 fig2 compositionOracle-assigned vs third-party CVEs per CPU quarterThe anatomy of the wave

Strip away the failed hypotheses and the discharge’s actual form emerges from the CVE metadata:

1,110 Oracle-assigned CVEs in a single quarter — 10.9x the historic norm. From 2021 by way of 2025, Oracle’s personal CNA contributed a remarkably regular 60–180 CVEs per CPU (imply: 102). The break is abrupt, not gradual: 2026’s personal January and April CPUs had been regular (68 and 109 Oracle CVEs).It is concentrated in Oracle’s large legacy utility codebases. E-Enterprise Suite leads with 410 risk-matrix entries — each one among them an Oracle-assigned CVE — adopted by Fusion Middleware (345 entries, 92% Oracle-assigned) and PeopleSoft (84 entries, 96% Oracle-assigned). Households constructed round bundled open supply, like Oracle Communications, stayed majority third-party. The wave hit the merchandise Oracle has been transport for twenty years, which is the place a brand new discovery functionality (or a brand new disclosure coverage) would discover essentially the most accrued materials.Contemporary, coordinated, and inside. The median July CVE was printed 0 days from the patch date — 75.1% inside three days of the CPU, the signature of internally found, coordinated disclosure — and reserved a median of simply 13 days earlier than launch. 75.6% had been fastened inside 30 days of any public disclosure.Exterior researchers did not trigger it. Oracle’s personal credit score assertion is the direct take a look at: the July advisory credit outdoors reporters for simply 54 CVEs — squarely throughout the 2021–2025 vary of 14–91 per quarter. Of the 1,110 Oracle-assigned CVEs, 95% carry no exterior credit score, versus roughly half in latest quarters. No matter discovered these flaws, it operates inside Oracle.Severity held its form — the brand new CVEs aren’t padding. The discharge general is nineteen.0% vital (CVSS ≥ 9.0) and 50.9% excessive, per historic CPUs, and the Oracle-assigned and third-party subsets have basically equivalent vital charges (18.9% and 18.6%). At this quantity that is 277 vital vulnerabilities in a single launch, together with everlasting fixes for the PeopleSoft pre-auth chain (CVE-2026-35273 / CVE-2026-35278, each CVSS 9.8) that ShinyHunters exploited towards 300+ servers at 100+ organizations in Could and June (Moxfive’s incident steerage).Virtually none of it’s known-exploited — but. Past the PeopleSoft pair, solely three CVEs within the launch carry known-exploited markers within the CVE report at time of writing (one a 2021 Linux kernel flaw). Similar-day CVEs lag in enrichment, so deal with this as a snapshot, not an all-clear.The run-rate is unprecedented. Counting CPUs and monthlies collectively, Oracle’s personal CNA has printed 1,541 CVEs in below seven months of 2026 — greater than in 2022, 2023, 2024, and 2025 mixed (1,395), and practically double its busiest prior full yr (811, in 2020) with 5 months nonetheless to go.6a60260530e91e9df40c89ba fig3 freshnessAge-at-patch distribution for July 2026 CVEs

Briefly: whichever approach Speculation 4 resolves, that is what it appears to be like like when a vendor discloses a decade’s value of vulnerabilities in its personal code in a single quarter.

The AI timeline

Why would a five-year-flat sequence leap an order of magnitude in ninety days? Oracle has, unusually, already answered on the report.

In late April 2026, Oracle’s safety weblog printed “Accelerating Vulnerability Detection and Response at Oracle”:

“Oracle is using AI, including frontier models, to improve how issues are found and to accelerate how fixes are delivered, including the introduction of monthly CSPUs.””Oracle has access to leading frontier AI models, including Anthropic’s Claude Mythos Preview and OpenAI’s most capable models through Trusted Access for Cyber.”

Oracle’s database staff went additional, urging prospects onto present launch updates as a result of, beginning April 2026, they “include fixes to vulnerabilities that could be identified with leading frontier AI models.”

The sequence within the information traces up with the sequence of bulletins:

2026EventOracle-assigned CVEsQ1Normal quarter (337-patch January CPU)68 in CPU — 0.67x baselineApril 7Anthropic proclaims Claude Mythos Preview: “thousands” of excessive/vital vulnerabilities discovered throughout main software program, “over 99% of the vulnerabilities we’ve found have not yet been patched”—Late AprilOracle proclaims AI-assisted detection and month-to-month cadence; April CPU nonetheless regular (109 Oracle CVEs, 1.07x baseline)—Could–JuneFirst month-to-month CSPUs (77 + 245 patches); Oracle’s calendar-quarter CVE output hits 3.6x baseline—July 21Record 1,449-patch CPU1,110 — 10.9x baseline6a6026bb30e91e9df40cd7c9 chart5 ai timelineOracle-CNA CVEs per CPU with the April 2026 bulletins annotated

Analyst protection related the dots the identical approach: SiliconANGLE’s Dave Vellante referred to as Oracle’s April advisory “a cybersecurity harbinger,” figuring out frontier-model vulnerability discovery because the catalyst and noting the April and July updates can be “the first to incorporate security hardening informed directly by testing with advanced AI models.”

Now, Oracle has by no means explicitly stated “the July CPU is large because AI found these bugs” — that causal hyperlink is our inference from timing, composition, and Oracle’s personal statements. Second, no impartial social gathering has audited how lots of the 1,110 had been AI-discovered, and the disclosure-policy different (Speculation 4) stays open. What the information establishes is the what — a tenfold disclosure surge, concentrated in Oracle’s personal code, instantly following Oracle’s AI announcement. The why rests on Oracle’s phrase.

How distinctive is that this? The apples-to-apples take a look at

A single vendor’s spike may nonetheless be an artifact of that vendor. So we listed each main vendor’s quarterly CVE output — as recorded within the official CVE Record, counting solely CVEs assigned by every vendor’s personal CNA — towards that vendor’s personal 2021–2024 quarterly common. (The peer baseline ends at 2024 intentionally: it is the final window that clearly predates AI-era discovery results, so any 2025–2026 acceleration reveals up within the a number of somewhat than being absorbed into the baseline.)

One orientation observe for studying the Oracle row: the desk counts CVEs printed per calendar quarter, throughout all of a vendor’s releases in that quarter. Oracle’s quarterly CPUs land in January (Q1), April (Q2), July (Q3), and October (This fall) — so the report July 21 CPU is the Q3 determine. Oracle’s elevated Q2 (3.6x) just isn’t the April CPU, which was regular; it is the primary two month-to-month CSPUs (Could 28 and June 16) stacking on high of it. The acceleration began with the monthlies and peaked with the quarterly launch.

Vendor2026-Q12026-Q22026-Q3Oracle0.7×3.6×10.5xMicrosoft1.2×2.3×2.6x †VMware (Broadcom)1.2×5.6x—Pink Hat1.1×2.3x—Adobe1.0x1.7x—SAP1.4×1.0x—Cisco1.2×0.8x—IBM1.4×1.4x—Apple1.4×1.4x—

† Partial quarter (three weeks, by way of July 21) — already above baseline. Different distributors’ partial-Q3 counts are withheld (—) as not significant. Oracle’s Q3 determine is full: its quarterly launch merely lands initially of the quarter (July 21). The 2 Oracle multiples on this piece measure various things: 10.9x compares CVEs within the July CPU towards the common CPU (102/quarter); 10.5x compares calendar-quarter printed CVEs towards the 2021–2024 quarterly imply.

6a60275d30e91e9df40d1073 fig5 peer multiplesCVE output listed to every vendor’s personal baseline

Two issues are true without delay:

1. The AI-era surge is industry-wide. On the Q2 column alone — the clear comparability — Microsoft, Pink Hat, VMware, and Adobe all ran 1.7–5.6x their very own baselines, whereas SAP, Cisco, IBM, and Apple stayed flat. Measured by Microsoft’s personal advisory feed (the MSRC API, which incorporates CVEs Microsoft ships fixes for however did not assign — bundled Chrome, open-source elements, and cloud CVEs), Microsoft’s Q2 reached 3,142 CVEs, roughly 4x its 2021–2023 common — the window earlier than Microsoft’s personal counting broadened (see caveats), and a broader unit than the CNA depend within the desk, which is why the 2 Microsoft figures differ.

The inflation is seen in all places you look: 48,185 CVEs had been printed in 2025, up 21% on high of 2024’s 38%; NIST introduced in April 2026 that the NVD will now not enrich each CVE; and Adobe and Cisco each moved to twice-monthly safety launch cadences. Behind it sit AI discovery applications — Google’s Massive Sleep, Microsoft’s Safety Copilot, Anthropic’s, XBOW’s — already transport CVEs at scale. Oracle is driving a wave, not inventing one.

2. Oracle’s magnitude is exclusive. The distributors that surged did so at 1.7–5.6x; Oracle’s July launch alone is an order of magnitude above its baseline, in its personal code, in a single quarter. Whether or not that displays essentially the most aggressive AI adoption within the {industry}, the biggest accrued inventory of undisclosed vulnerabilities, or a disclosure-policy shift driving an AI announcement — the trustworthy reply might be a few of every — Oracle’s July CPU is the only largest step-change in vendor vulnerability disclosure we will discover within the trendy CVE report.

What this implies for safety groups

The “record CPU” framing undersells it — plan for the brand new regular, not the outlier. Only one.8% of July’s CVEs had been repeats from the monthlies, which implies Oracle’s month-to-month CSPUs are additive, not previews. If discovery stays AI-accelerated, quarterly patch planning constructed round ~400 Oracle patches is now off by an element of three or extra, arriving on a monthly-plus-quarterly cadence.

Freshness cuts each methods. A median 13 days from CVE reservation to patch is genuinely quick remediation. But it surely additionally means defenders get no head begin: three-quarters of those vulnerabilities entered the general public report on patch day. And remediation at this pace and scale carries its personal operational threat — 1,449 patches produced on an accelerated pipeline can be 1,449 alternatives for regressions and incomplete fixes, so staged rollouts and post-patch validation matter extra, not much less, in an AI-paced patching regime. The identical class of discovery tooling is on the market to adversaries — Oracle’s personal advisory supplies body this system as a response to “AI-enabled cybersecurity threats,” and Anthropic’s Mythos announcement warned that over 99% of the vulnerabilities it discovered had been unpatched. The window between disclosure and exploitation was already shrinking; quantity at this scale strains each downstream course of — triage, testing, change home windows — between a vendor’s patch and your manufacturing programs.

Prioritize by publicity, not by depend. 277 vital CVEs in a single launch breaks CVSS-ranked to-do lists. The focus information tells you the place to begin: E-Enterprise Suite (410 entries, the biggest share of the discharge), Fusion Middleware (219 vulnerabilities exploitable over the community with out authentication, per Tenable), and PeopleSoft, the place the actively exploited ShinyHunters chain will get its everlasting repair. Web-facing situations of these three households are the discharge’s actual urgency.

For third-party threat groups, vendor patch latency simply turned a dwell sign. Your distributors’ Oracle estates — E-Enterprise Suite ERPs, PeopleSoft HR programs, WebLogic-hosted functions — simply acquired the biggest patch obligation within the platform’s historical past, and the PeopleSoft marketing campaign confirmed what unpatched publicity prices (HR and payroll information exfiltration at 100+ organizations). How shortly a vendor absorbs a 1,449-patch quarter — and whether or not their internet-facing Oracle surfaces keep stale — is now a measurable differentiator between distributors, not background noise.

Latest

Upgrades That Hold Insurance coverage Prices Down

Homeownership comes with loads of recurring prices, however your...

7 Causes to Use Actual Property Drone Images for Your Itemizing

On-line itemizing images usually form a purchaser’s first impression...

6 Frequent Errors Each First-Time Landlord Ought to Keep away from

Turning into a first-time landlord might be an thrilling...

Newsletter

Don't miss

Knowledge leakage dangers with DBHub MCP servers | Cybersecurity

Organizations preserve their databases behind firewalls for a cause: the information inside is the information they'll least afford to lose. A brand new class...

Larger Schooling TPRM in 2026: New Analysis Maps the Vendor Visibility Hole | Cybersecurity

Larger schooling establishments are essentially the most focused sector for cyberattacks. But the groups accountable for managing that danger usually face a structural drawback:...

Fixing Human Threat: Construct a Measurable, Safety-First Tradition | Cybersecurity

We have beforehand addressed the foundational issues of visibility and automatic human danger administration. Nonetheless, the ultimate, most enduring problem stays: how do you...

LEAVE A REPLY

Please enter your comment!
Please enter your name here