Oracle Releases August 2026 Critical Patch Update, Fixing 943 Vulnerabilities (78 Critical CVEs)
What Happened – Oracle’s August 2026 Critical Patch Update (CPU) ships patches for 943 security flaws across its product portfolio, including Oracle Fusion Middleware, Hyperion, Database Server, Autonomous Health Framework, Essbase and dozens of other families. 78 of the CVEs carry a Critical severity rating, and 182 can be exploited over the network without credentials.
Why It Matters for Compliance & Audit Readiness
- The CPU illustrates the volume of third‑party and open‑source components that can introduce high‑severity gaps in a trusted‑cloud environment – a classic control‑mapping scenario that SOC 2 programs must continuously monitor.
- Demonstrating timely patch adoption is a core evidence point for the Security principle (CC6.1) and for the Change Management controls (CC7.x) in a SOC 2 audit.
- Verisq’s Control Mapping capability automates evidence collection for each patched Oracle component, creating a defensible audit trail that satisfies both internal governance and external assessors.
Who Is Affected – Enterprises that run Oracle Database, Fusion Middleware, Hyperion, Essbase, Oracle Cloud applications, or any Oracle‑based ERP/CRM workloads across finance, manufacturing, retail, and public‑sector domains.
Recommended Actions
- Map each Oracle product version to the corresponding SOC 2 control (e.g., CC6.1 – Vulnerability Management).
- Ingest the Qualys QID list into your continuous‑compliance platform to auto‑correlate patch status with control evidence.
- Verify that all “network‑exploitable without credentials” findings are remediated within your patch‑window SLA and document the remediation dates for audit reviewers.
Source: Qualys Blog – Oracle Critical Patch Update, August 2026
Technical Notes – The update covers 6 new Database Server patches (max CVSS 9.6), 7 Autonomous Health Framework patches (max 8.8), 4 Essbase patches (max 9.8), and 262 patches each for Fusion Middleware and Hyperion. Approximately 6 % of the patches address non‑Oracle CVEs in bundled open‑source libraries.