Top/Articles/Oracle July 2026 CPU: 1,449 fixes and ten 10.0 unauth takeover flaws
oracle-critical-patch-update-2026-07-cover-en-update

Oracle July 2026 CPU: 1,449 fixes and ten 10.0 unauth takeover flaws

Oracle's July 2026 Critical Patch Update fixes a record 1,455 issues, including several CVSS 10.0 flaws that take over a server with no login. Affected are widely used middleware like WebLogic Server, Coherence, and Access Manager. Here's which products to prioritize and what to do now.

NewsPublished July 22, 2026Last updated July 29, 2026
Table of contents
Key takeaways

Oracle's July 2026 Critical Patch Update fixes a record 1,455 issues, including several CVSS 10.0 flaws that take over a server with no login. Affected are widely used middleware like WebLogic Server, Coherence, and Access Manager. Here's which products to prioritize and what to do now.

Correction, July 29, 2026 β€” the count is 1,449 fixes, not 1,455

When this article was published on July 21, 2026, its body and headline put the July 2026 Critical Patch Update (CPU) at "a record 1,455 fixes." The correct figure is 1,449. Tenable, heise, The Register, and Forbes β€” four independent reports β€” all agree on 1,449 (1,235 unique CVEs across 334 products), and nothing we found supports 1,455. The Fusion Middleware breakdown changes too: from 359 fixes (224 unauthenticated) to 355 (219 unauthenticated). Oracle's own advisory returns HTTP 403 to our requests, so we could not check the numbers against the primary source; the figures above come from those reports.

We are also correcting the claim that "WebLogic Server itself also carries 10.0 flaws." All ten 10.0-rated flaws in this CPU are in Fusion Middleware products. The highest score in WebLogic Server Core is 9.9 (CVE-2026-60206), and it requires a low-privileged login; the highest that needs no login is 9.8, in five CVEs. CVE-2026-60365, listed in our table at 10.0, is in the "WebLogic Server Proxy Plug-in" for third-party web servers, not the server itself. Oracle Access Manager's 10.0 (CVE-2026-60358) is real. The table and body have been updated. What has not changed as of July 29, 2026: no confirmed exploitation, no public PoC, and no CISA KEV listing for any of these.

Oracle has released its July 2026 quarterly security update (Critical Patch Update, CPU). It fixes a record 1,449 issues, ten of which let an attacker take over a server across the network with no login, rated the maximum severity of 10.0. All ten sit in the "Fusion Middleware" family that underpins many enterprise systems β€” Oracle Coherence, Oracle Access Manager, Oracle Data Integrator, and WebCenter Content among them.

If you run these products, internet-facing servers in particular need urgent attention. Oracle middleware like WebLogic has repeatedly been hit worldwide right after disclosure and suffered real takeovers β€” a perennial target. Here's what was released and which fixes to prioritize.

Key points (3 lines)

  • Oracle's July 2026 quarterly update is a record 1,449 fixes (1,235 unique CVEs, 334 products). Ten are rated 10.0, all in Fusion Middleware β€” Coherence, Access Manager, Data Integrator and others.
  • The largest counts are E-Business Suite (410), Fusion Middleware (355, with 219 remotely exploitable with no login), and PeopleSoft (84). WebLogic Server Core tops out at 9.9, and its highest no-login flaws are 9.8.
  • The fix is to apply the July 2026 CPU, prioritizing internet-facing WebLogic and other middleware. No exploitation, public PoC, or KEV listing has been observed.

What is Oracle's quarterly patch (CPU)?

Oracle's Critical Patch Update (CPU) is a bundle of security fixes the company ships every three months (January, April, July, October). Because it covers Oracle's vast portfolio at once β€” databases, Java, middleware like WebLogic, and business systems like E-Business Suite and PeopleSoft β€” a single release runs to hundreds or over a thousand fixes. This July 2026 edition came to 1,449 fixes covering 1,235 unique CVEs across 334 products, a record.

With that many, you have to zero in on "the ones that affect us" β€” and what deserves the most attention is anything rated at the top severity and exploitable with no login (unauthenticated). The per-family breakdown shows where the weight falls.

Product familyFixesRemotely exploitable
without login
E-Business Suite41045
Fusion Middleware355219
PeopleSoft8445
Whole CPU1,449
(1,235 unique CVEs)
334 products covered

E-Business Suite has the most fixes by count, but Fusion Middleware carries by far the highest share exploitable from outside with no login β€” 219 of 355. All ten 10.0-rated flaws land in that family as well, and Oracle itself strongly recommends applying the fixes as soon as possible. That is the case for starting with internet-facing middleware.

Who targets this, and why

The people who go after these unauthenticated Oracle-middleware flaws are attackers who mechanically sweep the internet for exposed WebLogic and similar servers. For ransomware crews and organized intrusion groups, a widely used core middleware like WebLogic is an ideal entry point. Once a fix ships, the technique is inferred from the diff within days, and unpatched servers are targeted en masse.

The attacker aims to run arbitrary code on the server with no login and take the whole system over. A successful takeover leads to theft of the business data the server handles, ransomware encryption and extortion, and a foothold deeper into the internal network. WebLogic has in fact had flaws from past CPUs exploited right after release and listed repeatedly on the U.S. CISA Known Exploited Vulnerabilities (KEV) catalog (see our roundup of WebLogic exploitation).

The damage isn't just the server admin's problem. If core systems or middleware are taken over, the entire business riding on them β€” customer data, data exchange with partners β€” is exposed. That is why you should act on the priorities below without delay.

The "no-login takeover" flaws to prioritize (examples)

Of the 1,449 fixes, the first to prioritize are those exploitable over the network with no login that fully compromise the server. Below are representative examples (severity and preconditions per NVD). All are fixed in the July 2026 CPU.

CVEProduct (component)SeverityPrecondition
CVE-2026-60217Oracle Coherence
(Core)
10.0Unauthenticated, network
CVE-2026-60358Oracle Access Manager
(Authentication Engine)
10.0Unauthenticated, network
CVE-2026-47056Oracle Data Integrator
(REST service)
10.0Unauthenticated, network
CVE-2026-60644WebCenter Content
(Web Content Management)
10.0Unauthenticated, network
CVE-2026-60365WebLogic Server
Proxy Plug-in
(not the server, 15.1.1.0.0 only)
10.0Unauthenticated, network
(no availability impact)
CVE-2026-60198 and 4 moreWebLogic Server itself
(Core)
9.8Unauthenticated, network
CVE-2026-60206WebLogic Server itself
(Core)
9.9Low-privileged login required

All ten 10.0 flaws are in Fusion Middleware products. WebLogic Server Core has no 10.0. Its highest is CVE-2026-60206 at 9.9, which still needs a login, even a low-privileged one. The no-login flaws in the server itself are CVE-2026-60198/60199/60200/60202/60204 at 9.8, and those are the practical top priority for any WebLogic exposed to the internet. CVE-2026-60365 carries the WebLogic name but is really the plug-in you put in front of a third-party web server such as Apache or IIS; only 15.1.1.0.0 is affected, and the impact is limited to disclosure and tampering, with no way to knock the server offline. If you don't run the plug-in, it doesn't apply to you.

Two related flaws get mixed into coverage of this release, so keep them separate. Reports that "the July CPU includes one flaw already used in attacks" refer to PeopleSoft's CVE-2026-35273, not to the WebLogic, Coherence, or Access Manager issues above (details in our article on the PeopleSoft zero-day exploitation). And CVE-2026-21962 β€” WebLogic Proxy Plug-in, rated 10.0, with a public PoC β€” belongs to the January 2026 CPU. For the July batch, as of July 29, 2026, no exploitation, no public PoC, and no CISA KEV entry has been observed.

Does it affect you, and what to prioritize

Not all 1,449 apply to you. First, inventory the Oracle products you run, then check only the CVEs for those products against the per-product CPU list. From there, this order helps you prioritize efficiently.

PriorityTargetWhy
TopInternet-facing
WebLogic / middleware
Unauth 9.8-10.0, directly targeted from outside
HighInternal
Fusion Middleware
219 of 355 unauth, usable for lateral movement
MediumE-Business Suite (410),
PeopleSoft (84), etc.
Business data and secrets concentrate here
OngoingDatabase / Java, etc.Apply on your regular schedule

WebLogic in particular sees repeated attacks abusing its proprietary protocols (T3/IIOP) for external communication. Even if you can't patch immediately, keeping those protocols and admin consoles unreachable from the internet β€” narrowing the entry points β€” greatly shrinks the attack surface.

What to do right now

The basic response is to apply the July 2026 CPU. Oracle's Critical Patch Update Advisory (July 2026) lists the applicable CVEs and where to get the patches, per product. Identify the products you run, and following the priorities above, patch internet-facing middleware first.

If you can't patch right away, useful stopgaps are to block WebLogic admin consoles and T3/IIOP traffic from the internet and restrict source addresses. But that only buys time β€” the real fix is the patch. Also check for unfamiliar admin accounts or suspicious traffic, in case you've already been compromised.

As of July 29, 2026, none of the flaws fixed in this CPU have been seen exploited, and no working PoC has been published. WebLogic-class middleware is still known for fast post-disclosure abuse, though. You can check whether anything has been added to the U.S. CISA catalog of actively exploited vulnerabilities in our tracker of actively exploited vulnerabilities (Japanese).

Summary

Oracle's July 2026 quarterly patch (CPU) fixed a record 1,449 issues, covering 1,235 unique CVEs across 334 products. The dangerous part is the ten 10.0 flaws that take over a server with no login, all concentrated in Fusion Middleware products β€” Coherence, Access Manager, Data Integrator, and WebCenter Content. Fusion Middleware alone accounts for 355 fixes, 219 of them remotely exploitable without authentication, and core systems like E-Business Suite (410) and PeopleSoft (84) are affected too.

The response is to inventory the Oracle products you run and apply the July 2026 CPU, patching internet-facing WebLogic and other middleware first. WebLogic Server itself has no 10.0 this quarter, but it does have five no-login 9.8 flaws, and it remains a product that gets exploited soon after disclosure. Don't get lost in the sheer count β€” act first on anything that is "unauthenticated, high severity, and internet-facing."

Sources

avatar-m-1

Backend Engineer / AWS / Django