Oracle Ships 943 Patches: CVE-2026-61241 Hits Max CVSS 10.0
Oracle's August 2026 monthly update brings 943 patches, 3 at CVSS 10.0 and 467 exploitable without login, concentrated in Hyperion and Fusion Middleware.
Table of contents
Oracle's August 2026 monthly update brings 943 patches, 3 at CVSS 10.0 and 467 exploitable without login, concentrated in Hyperion and Fusion Middleware.
On August 18, 2026, Oracle released its monthly Critical Security Patch Update (CSPU). It contains 943 patches, including three that carry the maximum CVSS score of 10.0 and 151 rated 9.0 or higher. Roughly half of them β 467 β are remotely exploitable without authentication.
The patches cluster in two places: Hyperion, used for consolidated financial closing, and Fusion Middleware, the foundation layer beneath enterprise systems β 262 patches each. E-Business Suite, which runs core business operations, follows with 120. In other words, a concentrated set of holes has surfaced in exactly the systems that Japanese enterprises rely on for financial close, procurement, and payment processing.
As of August 19, 2026, there is still no Japanese-language coverage of this release, and neither JPCERT/CC nor IPA has issued an advisory. This article lays out what was published and what to fix first.
Key points (three lines)
- Released August 18, 2026: 943 patches (925 unique CVE identifiers after removing duplicates). Three carry a CVSS score of 10.0, 151 are rated 9.0 or higher, and 467 are remotely exploitable without authentication.
- The heaviest concentrations are Hyperion with 262, Fusion Middleware with 262, and E-Business Suite with 120. All three 10.0 flaws sit within Hyperion and Fusion Middleware.
- No exploitation has been reported so far, and none of this release appears on the U.S. government's catalog. The next CSPU lands on September 15, 2026, and the quarterly Critical Patch Update on October 20.
Not a quarterly patch but a monthly one β and that distinction matters
Oracle changed how it ships fixes in 2026. Until then, everything arrived in the four annual batches of January, April, July, and October known as the Critical Patch Update (CPU). Since May 28, 2026, a monthly release (CSPU) covering the other months has been added on top. August's release is one of those monthly editions. We covered the change here when the first May edition shipped.
The problem is scale. Oracle describes the monthly releases as small, narrowly scoped supplements to the quarterly ones. The actual trajectory tells a different story.
| Date | Type | Patches |
|---|---|---|
| January 2026 | Quarterly | 337 |
| April 2026 | Quarterly | 481 |
| May 2026 | Monthly (first) | 35 |
| June 2026 | Monthly | 245 |
| July 2026 | Quarterly | 1,400+ |
| August 2026 | Monthly | 943 |
A monthly release that started at 35 patches reached 943 in three months. Security firm Tenable's analysis calls this a further blurring of the line between the monthly and quarterly releases. Put plainly, a volume roughly two-thirds the size of July's quarterly update now lands in an "off" month.
For the teams that run these systems, it means testing and deployment cycles built around four dates a year have effectively become monthly. The next release is September 15, 2026, followed by the quarterly update on October 20.
Where the patches landed
The table below draws on Oracle's published risk matrices, ordered by patch count. The rightmost column shows how many are remotely exploitable without authentication.
| Product family | What it does | Patches | Exploitable without authentication |
|---|---|---|---|
| Hyperion | Consolidated close, budgeting | 262 | 107 |
| Fusion Middleware | Application foundation, identity infrastructure | 262 | 182 |
| E-Business Suite | Accounting, procurement, HR operations | 120 | 27 |
| Commerce | E-commerce site platform | 66 | 47 |
| Siebel CRM | Customer management, sales enablement | 50 | 21 |
| Supply Chain | Production control, design data management | 46 | 18 |
| Virtualization | VirtualBox and other virtualization | 21 | 2 |
| PeopleSoft | HR, payroll, campus solutions | 15 | 7 |
| MySQL | Database | 9 | 5 |
| Total | 23 product families | 943 | 467 |
Across the release as a whole, about half the flaws need no authentication β but the distribution is far from even. Fusion Middleware accounts for 182 of its 262, and Commerce 47 of its 66. Both are products typically deployed facing the internet, which is where the prioritization starts.
One clarification: MySQL Server itself is not affected by this release. Oracle's Japanese-language MySQL account called this out explicitly; the components in scope are MySQL AI, MySQL Shell, the various connectors, and the Docker images.
Who targets these systems, and why
The attackers who go after products like these are the ones who scan the internet mechanically for exposed enterprise systems and sell access in bulk the moment they find it. The groups that break in, the groups that demand ransom, and the groups that resell stolen data are often entirely separate operations. As a rule, the work of diffing a patch and reverse-engineering an exploit begins the day after release.
Their goal is to reach the systems holding business data without passing authentication, then use that foothold to move laterally inside the network. Hyperion, the product with the largest share of this release, holds consolidated financial figures; E-Business Suite holds payment and procurement records. Unpublished pre-earnings numbers and supplier bank details command a premium both in ransom negotiations and on resale markets.
The damage arrives in two waves. The company itself absorbs system outages, delayed financial close, and the cost of an investigation that often cannot establish how much was seen. Its customers and business partners then receive breach notifications, or face fraudulent invoices built from stolen transaction records. This is not hypothetical: Oracle E-Business Suite was hit in 2025 by a large-scale extortion campaign exploiting a then-unknown flaw, and PeopleSoft saw educational institutions targeted heavily in June 2026. These 943 patches sit on the same continuum.
The three flaws rated 10.0
Severity is expressed on a ten-point scale. A CVSS score of 10.0 is assigned only when a flaw requires neither authentication nor user interaction and its impact extends beyond the affected product itself. Three flaws met that bar this month.
| Identifier | Product | What the component does | Affected versions |
|---|---|---|---|
| CVE-2026-61241 | Oracle Internet Directory | Central directory of employee accounts | 12.2.1.4.0 14.1.2.1.0 |
| CVE-2026-70880 | Hyperion Data Relationship Mgmt | Master data for accounts and org structures | 11.2.25.0.000 |
| CVE-2026-70921 | Hyperion Financial Management | Consolidation of financial results | 11.2.25.0.000 |
CVE-2026-61241 deserves particular attention: Oracle Internet Directory is the service that holds employee IDs and passwords in one place. Being able to reach it freely from outside is functionally the same as having an unlimited supply of badges to every internal system. The other two are both on the Hyperion side, covering the consolidation engine and the master data that defines the dimensions it consolidates along.
Hyperion leads the release overall with 262 patches, broken down as 78 for Financial Management, 67 for the platform layer, 36 for Calculation Manager, 35 for Data Relationship Management, and 32 for Financial Reporting. Oracle has not published Japanese deployment figures in recent years, but the product was reported to have more than 1,000 domestic customers as of 2014, and it still runs consolidated close processes at listed companies today. That creates a distinct operational problem: when the patch window overlaps with the quarterly close, taking the system down is a hard sell.
99 patches in a single product: what happened to Helidon
Counting the entries individually, a single product β Helidon β accounts for 99 of them, and 87 of those are exploitable without authentication. More than a tenth of the entire release sits in one product.
Helidon is Oracle's own Java development framework, treated as part of Fusion Middleware. All 99 entries are concentrated in a single component, the Imperative Web Server, which handles inbound network traffic. Affected versions span the 1.4, 3.2, and 4.5 lines. A cluster of this size in one component is most plausibly the result of an extensive automated input-generation testing campaign β fuzzing β whose findings were filed all at once.
Few Japanese organizations are likely to be using Helidon directly, but it is worth noting that it can be present unintentionally as part of a Fusion Middleware deployment. Check whether it appears anywhere in your own stack.
Is any of this being exploited right now?
The short answer: there are no reports of active exploitation of anything in this release so far. A full review of the August 18, 2026 edition of CISA's Known Exploited Vulnerabilities (KEV) catalog found none of the 925 CVEs listed. No proof-of-concept code has surfaced either.
That said, Oracle products are regulars on that catalog, with 45 entries to date. Most recently, CVE-2026-46817 in E-Business Suite was added on July 15, 2026 with a remediation deadline of just three days, and CVE-2026-35273 in PeopleSoft has been confirmed in ransomware activity. The right read is not "it's quiet, so we're fine" but "patch it before it lands on the list."
β What is confirmed
- βReleased August 18, 2026: 943 patches, 925 by CVE identifier (Oracle advisory)
- βThree flaws at CVSS 10.0, 151 rated 9.0 or higher
- βNothing from this release appears in CISA KEV (verified against the August 18, 2026 edition)
- βNext CSPU on September 15, 2026; quarterly CPU on October 20
? What remains unconfirmed
- ?The total exploitable without authentication β Oracle breaks this out only per product family, and the figure of 467 is our own sum of those subtotals
- ?Deployment scale in Japan β customer counts for Hyperion, Siebel, and PeopleSoft have not been published in recent years
- ?Future exploitation β there is no telling how long it will take for working exploits to be built from the patch diffs
No Japanese-language coverage yet
As of August 19, 2026, we have found no Japanese-language reporting on this release. JPCERT/CC has published zero Oracle-related advisories across all of 2026, and IPA's critical security notices have been limited to Java SE, issued only in step with the quarterly updates. Nothing was published for the May, June, or August monthly releases.
English-language coverage is barely better: Tenable's analysis is the only piece on this release, and the major international security outlets had not picked it up as of August 19. The quarterly updates draw simultaneous coverage everywhere, yet a monthly release of comparable size is slipping by in silence. Organizations that have built their patching decisions around four checkpoints a year may not even be aware the monthly releases exist.
For guidance on tracking vulnerability information relevant to Japan, see our roundup of critical vulnerabilities affecting Japanese enterprises.
What to do now
You do not need to read all 943 entries. Work through them in this order.
First, start with the Oracle products exposed to the internet. Fusion Middleware and Commerce combine a high proportion of flaws exploitable without authentication with a tendency to be deployed externally. Anything positioned to receive traffic from outside the organization β Oracle Internet Directory, WebLogic Server β takes top priority. WebLogic has been used in real-world attacks repeatedly, and it is in scope again this month.
Second, if you run Hyperion, settle the timing against your close calendar now. Two of the three 10.0 flaws are here, affecting version 11.2.25.0.000. Taking the system down mid-close genuinely is not an option, which is exactly why the deployment window needs to be locked in early β otherwise it slides to the next quarter by default.
Third, rebuild your process around a monthly cadence. If test environments and downtime windows are still being arranged on a four-times-a-year assumption, September 15 and then October 20 will arrive back to back. If full regression testing every month is unrealistic, a two-tier approach β monthly for internet-facing products, quarterly for everything else β is a more practical way to draw the line.
Fourth, inventory the components you did not know you had running, like Helidon. 99 patches in a single product is a good prompt to find out what is missing from your architecture documentation.
Summary
Oracle's monthly release of August 18, 2026 contains 943 patches: three at CVSS 10.0, 151 rated 9.0 or higher, and 467 exploitable without authentication. Hyperion, used for consolidated financial close, and Fusion Middleware, the foundation beneath enterprise systems, stand out with 262 patches each.
No exploitation has been reported so far, and none of this release appears on the U.S. government's catalog. But Oracle products are regulars there, and the most recent addition came with a three-day remediation deadline. With no Japanese-language information circulating yet, the organizations that notice first will be the ones that act first. The next release is September 15; the quarterly update follows on October 20.
Sources
- βΈOracle - Critical Security Patch Update Advisory - August 2026 (August 18, 2026)
- βΈOracle - August 2026 Risk Matrices (text version)
- βΈOracle - Critical Patch Updates, Security Alerts and Bulletins (upcoming release schedule)
- βΈOracle - Critical Patch Updates FAQ (on the role of the monthly releases)
- βΈTenable - Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs (August 18, 2026)
- βΈOracle Security Blog - Monthly Critical Security Patch Updates Begin May 28, 2026
- βΈSecurityWeek - Oracle Debuts Monthly Critical Security Patch Updates (May 6, 2026)
- βΈNVD - CVE-2026-61241 (Oracle Internet Directory, CVSS 10.0)
- βΈNVD - CVE-2026-70880 (Hyperion Data Relationship Management, CVSS 10.0)
- βΈNVD - CVE-2026-70921 (Hyperion Financial Management, CVSS 10.0)
- βΈCISA - Known Exploited Vulnerabilities Catalog (all entries checked against the August 18, 2026 edition)
- βΈThe Register - Oracle drops 1,449 security patches like it's the new normal (July 23, 2026)
- βΈJPCERT/CC - Advisories (2026) (confirmed to contain no Oracle-related entries)

Makoto Horikawa
Backend Engineer / AWS / Django