National Cyber Warfare Foundation (NCWF)

Oracle April 2026 Critical Patch Update Addresses 241 CVEs


0 user ratings
2026-04-21 22:48:46
milo
Blue Team (CND)

Oracle addresses 241 CVEs in its second quarterly update of 2026 with 481 patches, including 34 critical updates.



Key takeaways:



  1. The second Critical Patch Update (CPU) for 2026 contains fixes for 241 unique CVEs in 481 security updates
     

  2. 34 issues (7.1% of all patches) were assigned a critical severity rating
     

  3. Oracle Communications received the highest number of patches at 139, accounting for 28.9% of all patches
     



Background


On April 21, Oracle released its Critical Patch Update (CPU) for April 2026, the second quarterly update of the year. This CPU contains fixes for 241 unique CVEs in 481 security updates across 28 Oracle product families. Out of the 481 security updates published this quarter, 7.1% of patches were assigned a critical severity. High severity patches accounted for the bulk of security patches at 45.9%, followed by medium severity patches at 44.1%.


This quarter's update includes 34 critical patches across 22 CVEs.






































SeverityIssues PatchedCVEs
Critical3422
High22199
Medium212107
Low1413
Total481241


Analysis


This quarter, the Oracle Communications product family contained the highest number of patches at 139, accounting for 28.9% of the total patches, followed by Oracle Financial Services Applications at 75 patches, which accounted for 15.6% of the total patches.


A full breakdown of the patches for this quarter can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication.

























































































































































Oracle Product FamilyNumber of PatchesRemote Exploit without Auth
Oracle Communications13993
Oracle Financial Services Applications7559
Oracle Fusion Middleware5946
Oracle MySQL343
Oracle PeopleSoft217
Oracle E-Business Suite188
Oracle Analytics1511
Oracle Retail Applications1515
Oracle Siebel CRM1413
Oracle Java SE117
Oracle GoldenGate107
Oracle Enterprise Manager98
Oracle Virtualization91
Oracle Database Server84
Oracle Utilities Applications76
Oracle Hyperion64
Oracle Construction and Engineering43
Oracle Life Science Applications43
Oracle Supply Chain42
Oracle Blockchain Platform32
Oracle Commerce32
Oracle JD Edwards33
Oracle Adapter for Eclipse RDF4J22
Oracle Autonomous Health Framework21
Oracle REST Data Services22
Oracle Systems21
Oracle TimesTen In-Memory Database11
Oracle Hospitality Applications11


Solution


Customers are advised to apply all relevant patches in this quarter's CPU. Please refer to the April 2026 advisory for full details.


Identifying affected systems


A list of Tenable plugins to identify these vulnerabilities will appear here as they're released. This link uses a search filter to ensure that all matching plugin coverage will appear as it is released.


Get more information



Join Tenable's Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.


Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.



The post Oracle April 2026 Critical Patch Update Addresses 241 CVEs appeared first on Security Boulevard.



Research Special Operations

Source: Security Boulevard
Source Link: https://securityboulevard.com/2026/04/oracle-april-2026-critical-patch-update-addresses-241-cves/


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.