Top/Articles/Oracle Ships 943 Patches: CVE-2026-61241 Hits Max CVSS 10.0
oracle-critical-patch-update-2026-08-cover-en

Oracle Ships 943 Patches: CVE-2026-61241 Hits Max CVSS 10.0

Oracle's August 2026 monthly update brings 943 patches, 3 at CVSS 10.0 and 467 exploitable without login, concentrated in Hyperion and Fusion Middleware.

NewsPublished Aug. 19, 2026 Updated today
Table of contents
Key takeaways

Oracle's August 2026 monthly update brings 943 patches, 3 at CVSS 10.0 and 467 exploitable without login, concentrated in Hyperion and Fusion Middleware.

On August 18, 2026, Oracle released its monthly Critical Security Patch Update (CSPU). It contains 943 patches, including three that carry the maximum CVSS score of 10.0 and 151 rated 9.0 or higher. Roughly half of them β€” 467 β€” are remotely exploitable without authentication.

The patches cluster in two places: Hyperion, used for consolidated financial closing, and Fusion Middleware, the foundation layer beneath enterprise systems β€” 262 patches each. E-Business Suite, which runs core business operations, follows with 120. In other words, a concentrated set of holes has surfaced in exactly the systems that Japanese enterprises rely on for financial close, procurement, and payment processing.

As of August 19, 2026, there is still no Japanese-language coverage of this release, and neither JPCERT/CC nor IPA has issued an advisory. This article lays out what was published and what to fix first.

Key points (three lines)

  • Released August 18, 2026: 943 patches (925 unique CVE identifiers after removing duplicates). Three carry a CVSS score of 10.0, 151 are rated 9.0 or higher, and 467 are remotely exploitable without authentication.
  • The heaviest concentrations are Hyperion with 262, Fusion Middleware with 262, and E-Business Suite with 120. All three 10.0 flaws sit within Hyperion and Fusion Middleware.
  • No exploitation has been reported so far, and none of this release appears on the U.S. government's catalog. The next CSPU lands on September 15, 2026, and the quarterly Critical Patch Update on October 20.

Not a quarterly patch but a monthly one β€” and that distinction matters

Oracle changed how it ships fixes in 2026. Until then, everything arrived in the four annual batches of January, April, July, and October known as the Critical Patch Update (CPU). Since May 28, 2026, a monthly release (CSPU) covering the other months has been added on top. August's release is one of those monthly editions. We covered the change here when the first May edition shipped.

The problem is scale. Oracle describes the monthly releases as small, narrowly scoped supplements to the quarterly ones. The actual trajectory tells a different story.

DateTypePatches
January 2026Quarterly337
April 2026Quarterly481
May 2026Monthly (first)35
June 2026Monthly245
July 2026Quarterly1,400+
August 2026Monthly943

A monthly release that started at 35 patches reached 943 in three months. Security firm Tenable's analysis calls this a further blurring of the line between the monthly and quarterly releases. Put plainly, a volume roughly two-thirds the size of July's quarterly update now lands in an "off" month.

For the teams that run these systems, it means testing and deployment cycles built around four dates a year have effectively become monthly. The next release is September 15, 2026, followed by the quarterly update on October 20.

Where the patches landed

The table below draws on Oracle's published risk matrices, ordered by patch count. The rightmost column shows how many are remotely exploitable without authentication.

Product familyWhat it doesPatchesExploitable without
authentication
HyperionConsolidated close,
budgeting
262107
Fusion MiddlewareApplication foundation,
identity infrastructure
262182
E-Business SuiteAccounting, procurement,
HR operations
12027
CommerceE-commerce site
platform
6647
Siebel CRMCustomer management,
sales enablement
5021
Supply ChainProduction control,
design data management
4618
VirtualizationVirtualBox and other
virtualization
212
PeopleSoftHR, payroll,
campus solutions
157
MySQLDatabase95
Total23 product families943467

Across the release as a whole, about half the flaws need no authentication β€” but the distribution is far from even. Fusion Middleware accounts for 182 of its 262, and Commerce 47 of its 66. Both are products typically deployed facing the internet, which is where the prioritization starts.

One clarification: MySQL Server itself is not affected by this release. Oracle's Japanese-language MySQL account called this out explicitly; the components in scope are MySQL AI, MySQL Shell, the various connectors, and the Docker images.

Who targets these systems, and why

The attackers who go after products like these are the ones who scan the internet mechanically for exposed enterprise systems and sell access in bulk the moment they find it. The groups that break in, the groups that demand ransom, and the groups that resell stolen data are often entirely separate operations. As a rule, the work of diffing a patch and reverse-engineering an exploit begins the day after release.

Their goal is to reach the systems holding business data without passing authentication, then use that foothold to move laterally inside the network. Hyperion, the product with the largest share of this release, holds consolidated financial figures; E-Business Suite holds payment and procurement records. Unpublished pre-earnings numbers and supplier bank details command a premium both in ransom negotiations and on resale markets.

The damage arrives in two waves. The company itself absorbs system outages, delayed financial close, and the cost of an investigation that often cannot establish how much was seen. Its customers and business partners then receive breach notifications, or face fraudulent invoices built from stolen transaction records. This is not hypothetical: Oracle E-Business Suite was hit in 2025 by a large-scale extortion campaign exploiting a then-unknown flaw, and PeopleSoft saw educational institutions targeted heavily in June 2026. These 943 patches sit on the same continuum.

The three flaws rated 10.0

Severity is expressed on a ten-point scale. A CVSS score of 10.0 is assigned only when a flaw requires neither authentication nor user interaction and its impact extends beyond the affected product itself. Three flaws met that bar this month.

IdentifierProductWhat the component doesAffected versions
CVE-2026-61241Oracle Internet
Directory
Central directory of
employee accounts
12.2.1.4.0
14.1.2.1.0
CVE-2026-70880Hyperion Data
Relationship Mgmt
Master data for accounts
and org structures
11.2.25.0.000
CVE-2026-70921Hyperion Financial
Management
Consolidation of
financial results
11.2.25.0.000

CVE-2026-61241 deserves particular attention: Oracle Internet Directory is the service that holds employee IDs and passwords in one place. Being able to reach it freely from outside is functionally the same as having an unlimited supply of badges to every internal system. The other two are both on the Hyperion side, covering the consolidation engine and the master data that defines the dimensions it consolidates along.

Hyperion leads the release overall with 262 patches, broken down as 78 for Financial Management, 67 for the platform layer, 36 for Calculation Manager, 35 for Data Relationship Management, and 32 for Financial Reporting. Oracle has not published Japanese deployment figures in recent years, but the product was reported to have more than 1,000 domestic customers as of 2014, and it still runs consolidated close processes at listed companies today. That creates a distinct operational problem: when the patch window overlaps with the quarterly close, taking the system down is a hard sell.

99 patches in a single product: what happened to Helidon

Counting the entries individually, a single product β€” Helidon β€” accounts for 99 of them, and 87 of those are exploitable without authentication. More than a tenth of the entire release sits in one product.

Helidon is Oracle's own Java development framework, treated as part of Fusion Middleware. All 99 entries are concentrated in a single component, the Imperative Web Server, which handles inbound network traffic. Affected versions span the 1.4, 3.2, and 4.5 lines. A cluster of this size in one component is most plausibly the result of an extensive automated input-generation testing campaign β€” fuzzing β€” whose findings were filed all at once.

Few Japanese organizations are likely to be using Helidon directly, but it is worth noting that it can be present unintentionally as part of a Fusion Middleware deployment. Check whether it appears anywhere in your own stack.

Is any of this being exploited right now?

The short answer: there are no reports of active exploitation of anything in this release so far. A full review of the August 18, 2026 edition of CISA's Known Exploited Vulnerabilities (KEV) catalog found none of the 925 CVEs listed. No proof-of-concept code has surfaced either.

That said, Oracle products are regulars on that catalog, with 45 entries to date. Most recently, CVE-2026-46817 in E-Business Suite was added on July 15, 2026 with a remediation deadline of just three days, and CVE-2026-35273 in PeopleSoft has been confirmed in ransomware activity. The right read is not "it's quiet, so we're fine" but "patch it before it lands on the list."

βœ“ What is confirmed

  • βœ“Released August 18, 2026: 943 patches, 925 by CVE identifier (Oracle advisory)
  • βœ“Three flaws at CVSS 10.0, 151 rated 9.0 or higher
  • βœ“Nothing from this release appears in CISA KEV (verified against the August 18, 2026 edition)
  • βœ“Next CSPU on September 15, 2026; quarterly CPU on October 20

? What remains unconfirmed

  • ?The total exploitable without authentication β€” Oracle breaks this out only per product family, and the figure of 467 is our own sum of those subtotals
  • ?Deployment scale in Japan β€” customer counts for Hyperion, Siebel, and PeopleSoft have not been published in recent years
  • ?Future exploitation β€” there is no telling how long it will take for working exploits to be built from the patch diffs

No Japanese-language coverage yet

As of August 19, 2026, we have found no Japanese-language reporting on this release. JPCERT/CC has published zero Oracle-related advisories across all of 2026, and IPA's critical security notices have been limited to Java SE, issued only in step with the quarterly updates. Nothing was published for the May, June, or August monthly releases.

English-language coverage is barely better: Tenable's analysis is the only piece on this release, and the major international security outlets had not picked it up as of August 19. The quarterly updates draw simultaneous coverage everywhere, yet a monthly release of comparable size is slipping by in silence. Organizations that have built their patching decisions around four checkpoints a year may not even be aware the monthly releases exist.

For guidance on tracking vulnerability information relevant to Japan, see our roundup of critical vulnerabilities affecting Japanese enterprises.

What to do now

You do not need to read all 943 entries. Work through them in this order.

First, start with the Oracle products exposed to the internet. Fusion Middleware and Commerce combine a high proportion of flaws exploitable without authentication with a tendency to be deployed externally. Anything positioned to receive traffic from outside the organization β€” Oracle Internet Directory, WebLogic Server β€” takes top priority. WebLogic has been used in real-world attacks repeatedly, and it is in scope again this month.

Second, if you run Hyperion, settle the timing against your close calendar now. Two of the three 10.0 flaws are here, affecting version 11.2.25.0.000. Taking the system down mid-close genuinely is not an option, which is exactly why the deployment window needs to be locked in early β€” otherwise it slides to the next quarter by default.

Third, rebuild your process around a monthly cadence. If test environments and downtime windows are still being arranged on a four-times-a-year assumption, September 15 and then October 20 will arrive back to back. If full regression testing every month is unrealistic, a two-tier approach β€” monthly for internet-facing products, quarterly for everything else β€” is a more practical way to draw the line.

Fourth, inventory the components you did not know you had running, like Helidon. 99 patches in a single product is a good prompt to find out what is missing from your architecture documentation.

Summary

Oracle's monthly release of August 18, 2026 contains 943 patches: three at CVSS 10.0, 151 rated 9.0 or higher, and 467 exploitable without authentication. Hyperion, used for consolidated financial close, and Fusion Middleware, the foundation beneath enterprise systems, stand out with 262 patches each.

No exploitation has been reported so far, and none of this release appears on the U.S. government's catalog. But Oracle products are regulars there, and the most recent addition came with a three-day remediation deadline. With no Japanese-language information circulating yet, the organizations that notice first will be the ones that act first. The next release is September 15; the quarterly update follows on October 20.

Sources

avatar-m-1

Makoto Horikawa

Backend Engineer / AWS / Django