Oracle July 2026 Critical Patch Update Addresses 1,235 CVEs Across E-Business Suite, HRMS, and Fusion Middleware
Scope: Oracle E-Business Suite (Including Oracle HRMS), Oracle Fusion Middleware, Oracle PeopleSoft, Oracle Database, Oracle MySQL, Oracle Java SE (32 Product Families)
Severity: Red
Oracle released its largest ever Critical Patch Update on July 21, 2026, addressing 1,235 unique CVEs across 1,449 patches in 32 product families, with 261 patches carrying critical severity ratings and approximately 663 vulnerabilities exploitable remotely without authentication. Oracle E-Business Suite received the highest number of patches at 410, including CVE-2026-62565 in Oracle HRMS US Payroll Year End (CVSS 7.1), which allows a low-privileged network attacker to access all HRMS payroll data and make unauthorized modifications to sensitive employee and payroll records across versions 12.2.3 through 12.2.15. Oracle describes this quarter's volume as driven largely by AI-assisted vulnerability discovery compressing disclosure timelines. Organizations running any Oracle product must apply the July 2026 CPU immediately, prioritizing internet-exposed Oracle E-Business Suite, Fusion Middleware, and PeopleSoft deployments, and refer to Oracle's advisory for the specific patch availability document applicable to each product version.
The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.