Top/Articles/Oracle Monthly CSPU and the ORDS CVSS 10.0: Current Status and Safe Versions
oracle-cspu-may-2026-monthly-launch-cvss-10-cover-en

Oracle Monthly CSPU and the ORDS CVSS 10.0: Current Status and Safe Versions

On May 28, 2026, Oracle switched its quarterly CPU to a monthly CSPU. The first wave shipped 35 patches, including a CVSS 10.0 in Oracle REST Data Services (CVE-2026-46840), 12 for E-Business Suite, 3 for Database, and 1 for Hospitality OPERA 5. The Cl0p E-Business Suite zero-day campaign is the backdrop.

NewsPublished May 29, 2026Last updated July 24, 2026
Table of contents
Key takeaways

On May 28, 2026, Oracle switched its quarterly CPU to a monthly CSPU. The first wave shipped 35 patches, including a CVSS 10.0 in Oracle REST Data Services (CVE-2026-46840), 12 for E-Business Suite, 3 for Database, and 1 for Hospitality OPERA 5. The Cl0p E-Business Suite zero-day campaign is the backdrop.

Oracle REST Data Services (ORDS), Oracle's official gateway for exposing Oracle Database as REST APIs, has a worst-case flaw in versions 24.2.0 through 26.1.0: CVE-2026-46840, CVSS 10.0, full remote takeover with no authentication. It was fixed in the May 2026 monthly Critical Security Patch Update (CSPU) published on May 28, 2026. If you have applied that patch, or run ORDS 26.2 or later (released July 2, 2026), no action is needed. Oracle E-Business Suite 12.2.3–12.2.15 received 12 patches in the same CSPU, and one of them — CVE-2026-46817 in the Payments component — was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on July 15, 2026, meaning it is being used in real attacks. If you haven't patched, close these two first.

The May CSPU was the first release of Oracle's new monthly cadence, replacing the once-a-quarter Critical Patch Update (CPU) rhythm. The monthly schedule has since held: the second CSPU landed on June 16 (245 patches for 243 CVEs), and the quarterly CPU followed on July 21 with a record 1,235 CVEs. "Oracle patches monthly" is no longer a plan. It is an established fact.

The backdrop is the Cl0p ransomware group's mass exploitation of Oracle E-Business Suite (CVE-2025-61882) that ran from August 2025. A quarterly cadence left a multi-week-to-multi-month gap between a CISA warning and the next CPU, and Oracle decided that was untenable. Oracle's official blog describes monthly CSPUs as "smaller and more focused," and disclosed that Anthropic's Claude and OpenAI's models are now embedded in Oracle's vulnerability detection and response workflows.

Oracle CSPU May 2026 — what shipped, at a glance

E-Business Suite dominates the count; ORDS carries the CVSS 10.0.

Product lineCountTop
CVSS
Unauth.
RCE?
Where it lives
Oracle REST
Data Services
(ORDS)
310.0
(CVE-2026-46840)
YesREST API gateway
for Oracle DB
Oracle
E-Business Suite
129.9
(CVE-2026-46822/
46824)
3 of 12
are unauth.
HR, finance,
procurement,
sales backbone
Oracle
Database Server
39.0
(CVE-2026-46833)
Yes
(AC:H)
Finance, public
sector, SI
Oracle
Hospitality OPERA 5
19.8
(CVE-2026-34311)
YesGlobal hotel chain
reservation / PMS
Others
(various)
16
Total3510.0

The unauthenticated, network-reachable ones are typically hit through internet-facing ORDS APIs, or post-intrusion lateral movement once an attacker is already on the internal network. ORDS at CVSS 10.0 means complete system takeover. And one of these 35 has already crossed from theory into practice: CVE-2026-46817 in E-Business Suite Payments entered the KEV catalog on July 15, 2026, a month and a half after publication.

Why Oracle switched from quarterly to monthly

Oracle's quarterly CPU has run on the third Tuesday of January, April, July, and October for over two decades — an industry-standard cadence that fit neatly into enterprise customers' once-a-quarter maintenance windows.

Then 2025 H2 happened. The Cl0p ransomware group mass-exploited a zero-day in the Concurrent Processing component of Oracle E-Business Suite (later assigned CVE-2025-61882, CVSS 9.8), exfiltrating data from multiple large enterprises. Oracle published an emergency alert; CISA added it to the KEV (Known Exploited Vulnerabilities) catalog. But until the next quarterly CPU, every E-Business Suite operator worldwide sat in a "we have no patch to apply" window.

Monthly CSPUs are designed to shrink that window to "at most 30 days." Oracle's official announcement frames them as "smaller and more focused," but for operators this means swapping "quarterly spring cleaning" for "twelve small patch waves a year," with twelve test plans and twelve maintenance windows. Oracle also explicitly stated that Anthropic's Claude and OpenAI's models are now part of its vulnerability detection pipeline — AI-accelerated triage is effectively a prerequisite for going monthly.

The quarterly CPU does not go away; monthly CSPUs run alongside it. That combined schedule has now been carried out. The June 16 CSPU delivered 245 patches for 243 CVEs (122 rated Critical; Fusion Middleware led with 106, E-Business Suite had 55). The July 21 quarterly CPU was Oracle's largest ever: 1,235 CVEs and 1,449 security updates across 32 product families, including the biggest E-Business Suite batch on record, topped by a CVSS 9.9 in Oracle Database Server (versions 19.3–23.26.2).

The "exploited during the gap" problem that drove the monthly switch has already repeated itself. CVE-2026-35273, a missing-authentication zero-day in PeopleSoft PeopleTools (Oracle's HR and finance package), was exploited by the ShinyHunters group (UNC6240) against more than 100 organizations and 300+ PeopleSoft servers between May 27 and June 9. It entered the KEV catalog on June 12 with known ransomware use; the permanent fix only shipped in the July 21 CPU. Shortening the patch interval helps, but attackers are still faster.

Why CVE-2026-46840 (ORDS, CVSS 10.0) is the must-fix

CVSS 10.0 is the theoretical maximum of CVSS v3.1; it only appears when every metric maxes out. The exact profile here is AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H — network, low complexity, no auth, no user interaction, scope change, full impact on confidentiality, integrity, and availability.

Oracle REST Data Services (ORDS) is Oracle's official gateway for exposing Oracle Database tables, views, and stored procedures as REST endpoints. Many shops put ORDS in front of "internal DB → external API" and "internal web app → DB" data flows, which means the blast radius isn't ORDS itself — it propagates to the Oracle Database behind it. The S:C (scope change) flag in the CVSS vector encodes exactly this propagation.

Affected ORDS versions are 24.2.0 — 26.1.0. ORDS commonly sits in the DMZ or behind a public load balancer, putting a CVSS 10.0 hole directly on internet-reachable infrastructure with no authentication wall. The fix shipped as the May CSPU patch via My Oracle Support and is carried in subsequent ORDS releases; the current release is 26.2, published July 2, 2026, and anything from 26.2 onward is clear of this flaw.

The exploitation picture needs careful reading. As of July 23, 2026, CVE-2026-46840 is not listed in the KEV catalog. At the same time, several secondary sources are circulating: a GitHub repository claiming to be a PoC (proof-of-concept exploit code), and security blogs stating the flaw is "already exploited and KEV-listed." The KEV claim contradicts the actual catalog (version 2026.07.23), so the exploitation claims remain unverified. That said, code claiming to be a working exploit being in circulation is not a reason to leave an unpatched ORDS exposed.

Who targets these holes, and what they take

Attackers targeting Oracle have professionalized sharply over the past year, led by Cl0p. Every CSPU release is, from the attacker side, the starting gun of the "race to weaponize before customers patch."

The buyers and operators sizing up these holes are concrete people: Cl0p and Cl0p-rebadged Eastern-European ransomware affiliates, industrial-espionage crews chasing finance and HR data inside Japanese and US enterprises running E-Business Suite, card-fraud rings hunting hotel reservation systems and stored card data, and double-extortion operators who want full Oracle Database snapshots as ransom leverage. What they actually pull out is not abstract — for a Japanese enterprise, that means the HR database of every employee's salary and bonus, the procurement database of supplier master records and payment terms, the sales database of unpublished order backlog, the cost-accounting module's internal margins, scanned PDFs of approvals and signed contracts, and the finance team's bank-transfer templates. The moment one externally-reachable CVE among these 35 is triggered, every record above is copied to the attacker's side.

Reconnaissance is heavily automated. A Shodan query for response bodies containing ords/ or /OA_HTML/ enumerates exposed E-Business Suite and ORDS instances; cross-referencing the CSPU release date and the affected component names produces a mechanical "list of targets to try within a week of release." Cl0p demonstrated in 2025 that they can hit production E-Business Suite environments even before public PoCs exist, and they race to extract value out of the gap between CSPU release and customer rollout. Monthly cadence narrows that gap, but it also means "the week right after each CSPU is now a hot zone" for every Oracle shop. CVE-2026-46817 reaching the KEV catalog a month and a half after the May CSPU shows this reading was not paranoia.

CVSS 10.0 is just the technical ceiling for "one server taken over." What an enterprise actually loses is the month-end financial close data, pre-earnings-announcement financials, the cost structure of the company's top-margin product line, the multi-year SAP-to-Oracle migration plan, and — for hotel chains — the loyalty program data and stay history of millions of guests. Teams that lived through Cl0p's 2025 Oracle E-Business Suite campaign know exactly why patch releases like this are never a far-away event.

Three-layer blast-radius table

DeploymentIn reachOut of reach
(needs another CVE)
Mid-tier SI
operating many
customer tenants
DMZ ORDS
 instances
Customer EBS
 Payments / Procurement
Oracle Database
 connection strings
Customer-side
 ADF / SSO
Adjacent systems
 run by a different SI
Enterprise
backbone EBS
(self-operated)
All HR / finance /
 procurement /
 sales masters
Month-end close data
Bank transfer
 templates
Performance metrics
Hypervisor
Active Directory
 (reachable through
 open egress, though)
Hotel / travel
OPERA 5
All reservation
 records
Stay history
Loyalty program
 member DB
Check-in/out logs
PCI DSS-compliant
 card vault (if
 tokenization layer
 is upstream)

The mid-tier SI case is especially sharp: one compromised ORDS instance can leak connection strings for many downstream customer databases at once. Given how contractual liability is divided, the SI's response speed feeds directly into customer indemnity exposure.

Per-CVE notes for the May CSPU Criticals

Authoritative per-CVE details live in the Oracle advisory.

CVE-2026-46840: ORDS, unauthenticated RCE (CVSS 10.0)

Hits ORDS 24.2.0 — 26.1.0 with AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. HTTPS-reachable, no auth needed. The scope-change flag means the impact propagates from ORDS to the Oracle Database it fronts. As of July 23, 2026 it is not in the KEV catalog, though purported PoC code circulates and secondary sources claim active exploitation (unverified against the catalog itself; see above). Applying the May CSPU patch or updating to ORDS 26.2+ closes it.

CVE-2026-46775: ORDS, authenticated full takeover (CVSS 9.9)

Same ORDS version range. A low-privileged authenticated attacker can take over ORDS via HTTPS. Patch alongside CVE-2026-46840.

CVE-2026-46839: ORDS, privilege escalation (CVSS 9.9)

Third ORDS 24.2.0 — 26.1.0 finding. A low-privileged user gets full confidentiality, integrity, and availability impact. Three ORDS criticals in one release, all 9.9 or higher.

CVE-2026-46822: E-Business Suite iAssets (CVSS 9.9)

EBS 12.2.3 — 12.2.15, iAssets (fixed-asset management) component. HTTP-reachable, low-privileged attacker takes over. iAssets is widely used in Japanese listed companies' finance systems.

CVE-2026-46824: E-Business Suite Universal Work Queue (CVSS 9.9)

Same EBS range. Work Provider Site Level Administration is the entry path. Scope-change flag means impact escapes Universal Work Queue and reaches adjacent components.

CVE-2026-46817: E-Business Suite Payments (CVSS 9.8)

EBS 12.2.3 — 12.2.15 Payments / File Transmission, unauthenticated, HTTP-reachable. Full impact on confidentiality, integrity, and availability. This one crossed from theory into practice: it was added to CISA's KEV catalog on July 15, 2026 (federal remediation deadline July 18), making it the first of the May CSPU's 35 patches confirmed to be used in real attacks. If your E-Business Suite is unpatched, apply this one first.

CVE-2026-46819: E-Business Suite Internet Procurement Connector (CVSS 9.1)

Same EBS range, Internet Procurement Connector. Unauthenticated remote attack enabling create/delete/modify on critical data. Availability is untouched (A:N), but write-tampering procurement records is a financial-audit problem on its own.

CVE-2026-46833: Oracle Database Server Net Service (CVSS 9.0)

Oracle Database Server 23.4.0 — 23.26.2, Net Service component. TLS-reachable, unauthenticated, but high attack complexity (AC:H). Scope change reaches Oracle Database itself — top priority for finance, public sector, and major SI teams.

CVE-2026-34311: Hospitality OPERA 5 (CVSS 9.8)

Oracle Hospitality OPERA 5 Property Services 5.6.19.24 / 5.6.22 / 5.6.25.19 / 5.6.27.6 / 5.6.28. Unauthenticated remote attack. OPERA 5 is the reservation/PMS backbone for global hotel chains; on a successful hit, every reservation record and loyalty profile is exposed.

Other EBS High CVEs (CVE-2026-46820 / 46826 / 46827 / 46837)

Four EBS High issues in the 8.5 — 8.8 range: Financials Common Modules (46820), Payroll Internal Operations (46826), Payroll Self Service Manager (46827), Flow Manufacturing (46837). All require low-privileged authenticated access; Payroll in particular is a fast path to every employee's personal information and bank details — HR departments should treat it as same-week urgent.

Three structural changes monthly CSPUs bring to operations

Monthly cadence isn't just "patches 4× more often." It restructures the maintenance workflow in three ways. Note that the original "smaller and more focused" framing was contradicted as early as the second release: the June CSPU carried 243 CVEs, so plans must assume the monthly volume swings widely.

ChangeQuarterly CPU eraMonthly CSPU era
Maintenance
windows
4 / year,
each large patch wave
(tens of CVEs)
12 / year,
size varies by month
(May: 35, June: 243)
Test planQuarterly,
2–4 weeks of
full testing
Monthly,
prioritized
short-cycle testing
SI service
contracts
Quarterly patch
application fee
(monthly-amortized)
Monthly patch
application — must
renegotiate

In Japan, many SI-customer Oracle service contracts priced "quarterly CPU application" as the unit of work; the monthly CSPU change immediately triggers contract review. IT departments should re-check the "Oracle patch application" clauses in their existing contracts.

Five checks to run now

If you operate Oracle E-Business Suite, ORDS, or Oracle Database, work through these in order.

#ActionWhat that actually means
1Check ORDS
version
Confirm the May CSPU
patch is applied, or that
you run 26.2+ (released
July 2, 2026). If neither,
update now, DMZ first.
2Verify EBS
12.2.3 — 12.2.15
If your EBS is in this range,
verify patch status starting
with KEV-listed Payments
(CVE-2026-46817), then
iAssets / Universal Work Queue.
3Review SI
service contracts
Reframe the "Oracle patch
application" clauses from
quarterly assumption to
monthly cadence; prepare
renegotiation terms.
4Tighten WAF
around DMZ ORDS
Until patches land,
tighten ORDS API auth checks,
block unused HTTP methods,
throttle rate limits.
5Make monthly
CSPU calendar
operational
Track Oracle's security
alerts page for each month's
CSPU and fold it into standing
reviews (release dates move:
May 28, then June 16).

Since 2025's Cl0p campaign, Oracle E-Business Suite has an established economic incentive for attackers. With the May CSPU's own CVE-2026-46817 now in the CISA KEV catalog, "this cannot wait for the next monthly CSPU" is no longer a projection — it is on the record.

Closing — monthly is not "easier," it's "less hiding room"

Oracle's monthly CSPU shift is not a comfort move for customers. It lays bare the defender's bind: Oracle has to compress its window-of-exposure against Cl0p-class operators from quarterly down to monthly. CSPU #1 carrying a CVSS 10.0 and eleven Criticals, and CSPU #2 ballooning to 243 CVEs, can also be read as the result of Oracle's new AI-assisted internal vulnerability detection — long-dormant issues surfacing all at once.

The operational homework has become real, too. Quarterly-based service contracts, change-management processes, and test-effort allocations are no longer things to rebuild "before the change arrives" — after the May and June CSPUs and the July CPU, the monthly machinery should already be running.

Where things stand as of July 23, 2026: the ORDS CVSS 10.0 (CVE-2026-46840) is fixed by the May CSPU patch and in ORDS 26.2+, with no KEV listing (secondary exploitation claims remain unverified). E-Business Suite's CVE-2026-46817 entered the KEV catalog on July 15, so unpatched environments are top priority. And as the PeopleSoft zero-day campaign (CVE-2026-35273) showed, attackers do not wait for the patch calendar, monthly or not. Check your versions, apply what applies.

References

avatar-m-1

Makoto Horikawa

Backend Engineer / AWS / Django