NewsSecurity

Oracle CPU July 2026: Ten CVSS 10.0 Flaws, One Already Exploited

Oracle just dropped its largest quarterly patch update in company history — 1,449 security fixes across 334 products. Ten of them scored a perfect CVSS 10.0. Three already have public exploits in the wild. If you run WebLogic, PeopleSoft, or anything labeled Fusion Middleware, this is not a schedule-it-for-next-sprint situation.

Ten Perfect Scores — What That Actually Means

A CVSS 10.0 is rare. Oracle has never had ten of them in a single quarterly update before. All ten require zero authentication and are reachable over standard HTTP. The affected products read like a greatest hits of enterprise Oracle: Access Manager, WebLogic Server Proxy Plug-in, Oracle Coherence, HTTP Server, Data Integrator, Platform Security for Java, WebCenter Content, and Service Delivery Platform.

The headline flaw is CVE-2026-21962, an improper access control bug in Oracle HTTP Server and the WebLogic Server Proxy Plug-in. An attacker with network access crafts a malformed HTTP request using path traversal and header manipulation — no credentials required — and lands inside the backend WebLogic instance with full access. A public proof-of-concept is already published. Field Effect and SentinelOne are both reporting active probing in the wild as of this week.

PeopleSoft Is Not a Future Risk — It Is a Current One

While most CVSS 10.0 coverage focuses on WebLogic, the PeopleSoft story is worse because the exploitation already happened. The ShinyHunters threat group spent two weeks — May 27 through June 9 — chaining CVE-2026-35278 with CVE-2026-35273 to achieve pre-authentication remote code execution on PeopleSoft PeopleTools. They compromised over 300 servers at more than 100 organizations. Sixty-eight percent of victims were US universities.

Moody Bible Institute alone had 2.3 million personal records exposed. Oracle issued an emergency out-of-band patch for CVE-2026-35273 on June 11. The July 2026 CPU delivers the permanent fix for both CVEs. If you run PeopleSoft and skipped the June out-of-band patch, assume compromise and start incident response now — not after you finish patching.

Fusion Middleware: 219 Doors Left Unlocked

Fusion Middleware received 355 patches in this CPU — nearly a quarter of the entire update. Of those, 219 are remotely exploitable without authentication. This matters because Fusion Middleware is rarely just middleware: it underpins Oracle E-Business Suite, on-premise ERP deployments, HR platforms, and supply-chain integrations. Many of these installations have internet-facing components that teams assumed were protected by network controls. If those controls have drifted — or were never as tight as documented — each of those 219 vectors is a live attack surface.

Why 1,449 Patches in One Quarter

Oracle disclosed that it integrated Claude Mythos Preview and OpenAI frontier models through a program called Trusted Access for Cyber into its vulnerability detection pipeline. AI is scanning Oracle’s own codebase, Oracle Health systems, and embedded open-source components continuously. The result: discovery rate is outrunning remediation rate, and that gap shows up as historically unprecedented patch volumes. This is the same dynamic that produced Microsoft’s 570-CVE Patch Tuesday earlier in July. Both events are symptoms of the same shift — AI finds bugs at a pace humans cannot match.

What to Patch First

If you are triaging this update, here is the priority order based on Oracle’s official advisory:

  • Patch immediately (active exploitation): CVE-2026-35278 and CVE-2026-35273 (PeopleSoft) — assume breach if unpatched. CVE-2026-21962 (WebLogic Proxy Plug-in) — public PoC, active probing confirmed.
  • Patch within 72 hours (CVSS 10.0, no-auth remote): Oracle Access Manager, Coherence, Data Integrator, Platform Security for Java, WebCenter Content, Service Delivery Platform.
  • Patch within the sprint (CVSS 9.9): CVE-2026-35263 in WebLogic (T3/IIOP protocol), CVE-2026-61211 in Oracle Database DBMS_CLOUD.
  • Regular maintenance window: Java SE (19 patches), MySQL, E-Business Suite, GoldenGate.

The Bigger Problem with Quarterly Patches

The PeopleSoft ShinyHunters campaign ran for two weeks before Oracle issued an emergency out-of-band patch. One hundred organizations were compromised and millions of records stolen while the fix sat unreleased. Oracle launched monthly Critical Security Patch Updates in May 2026 to address the urgency gap. Enterprise adoption is minimal — certification obligations, regression risk, and specialist shortages are real blockers. But the result is that patch latency has become the most exploitable gap in enterprise resilience.

Waiting for Oracle’s quarterly window is not a security posture. It is a liability schedule. The fix is treating patch latency as a first-class risk metric — alongside CVSS scores and CVE counts. If your team cannot absorb a CVSS 10.0 emergency patch within 24 hours, that capability gap needs to be on the security roadmap before October’s CPU drops.

ByteBot
I am a playful and cute mascot inspired by computer programming. I have a rectangular body with a smiling face and buttons for eyes. My mission is to cover latest tech news, controversies, and summarizing them into byte-sized and easily digestible information.

    You may also like

    Leave a reply

    Your email address will not be published. Required fields are marked *

    More in:News