Oracle released its July 2026 Critical Patch Update (CPU) on July 21, delivering 1,449 security fixes across 1,235 unique CVEs, the largest CPU in the company’s history. The release spans 32 product families, with the heaviest concentration in Oracle E-Business Suite, Oracle Fusion Middleware, Oracle Communications, and PeopleSoft.
Nine of these CVEs received a perfect CVSS 10.0 score. All nine sit inside Oracle Fusion Middleware, a product family that many enterprises expose directly to the internet through HTTP Server, WebLogic, and Identity Manager deployments. Two hundred twenty-eight CVEs in total carry a critical severity rating.
While Oracle recommends immediate installation of the July CPU, production patch cycles often require extensive testing and change management. During that window, publicly exposed Oracle applications remain at attractive targets, and one CVE pair (CVE-2026-35273) in this release was already being exploited before Oracle had a permanent fix ready.
This bulletin focuses on the Oracle vulnerabilities most likely to be exploited on internet-facing deployments, and how AppTrana WAAP protects against them.
Oracle July 2026 CPU Highlights
| Category | Details |
| Release | Oracle Critical Patch Update, July 2026 |
| Total Security Fixes | 1,449 patches across 1,235 unique CVEs |
| Highest Severity | CVSS 10.0 (9 unique CVEs, all in Fusion Middleware) |
| Critical Severity CVEs | 228 |
| Primary Risk | Unauthenticated remote code execution |
| Internet-Facing Products | Oracle HTTP Server, Fusion Middleware, E-Business Suite, PeopleSoft |
| Active Exploitation | PeopleSoft PeopleTools chain (CVE-2026-35278, CVE-2026-35273), mass exploited by ShinyHunters since May 27 |
| Recommended Action | Prioritize patching internet-facing systems; virtual patching in place for AppTrana customers |
Critical Oracle Web Vulnerabilities
Oracle PeopleSoft: The Vulnerability Already Under Attack
CVE-2026-35278 and CVE-2026-35273 are chained pre-authentication vulnerabilities in PeopleSoft PeopleTools that ShinyHunters mass-exploited between May 27 and June 9, before this CPU existed. The campaign compromised more than 300 servers across 100-plus organizations, 68% of them US universities, with Moody Bible Institute alone disclosing 2.3 million records exposed. Oracle issued an out-of-band patch for CVE-2026-35273 on June 11. This CPU delivers the permanent fix for both CVEs in the chain. Any PeopleTools instance that missed the June 11 patch should be treated as potentially compromised.
Oracle HTTP Server / WebLogic Proxy Plug-in
CVE-2026-21962 and CVE-2026-60365 are both CVSS 10.0, both unauthenticated, and both hit the same HTTP Server / WebLogic Server Proxy Plug-in surface. CVE-2026-21962 also carries over unresolved risk from the January 2026 CPU cycle, so environments that patched only the January round remain exposed to this July disclosure.
Oracle E-Business Suite
CVE-2026-60880 is a CVSS 9.8 unauthenticated takeover of the Work in Process module, in the same product family as CVE-2026-46817, which is already on CISA’s KEV list. E-Business Suite commonly supports finance, procurement, and HR operations, raising the stakes of any exposed instance.
Oracle Fusion Middleware and Identity Manager
CVE-2026-60773 and CVE-2026-62549 are additional CVSS 9.8 unauthenticated RCE vulnerabilities in Fusion Middleware. Oracle Identity Manager carries two more, CVE-2026-35268 and CVE-2026-21992, both tracing the same vulnerability family as CVE-2025-61757, another CISA KEV entry.
Why These Oracle Vulnerabilities Demand Immediate Patching
Oracle applications frequently support business-critical operations and integrate with external portals, APIs, and partner services. Vulnerabilities affecting these web-facing components become high-value targets quickly once disclosed, and the PeopleSoft chain in this CPU shows attackers don’t always wait for disclosure at all.
Enterprises typically need maintenance windows and compatibility testing before deploying CPU patches into production. That creates a temporary exposure window during which internet-facing Oracle deployments remain reachable.
Security teams should identify internet-facing Oracle deployments, prioritize the vulnerabilities above, and accelerate patch deployment wherever operationally feasible.
Oracle CPU July 2026: Recommended Actions
The steps below sequence remediation by actual exposure and risk:
- Patch immediately: Apply the July 2026 Oracle CPU across all supported environments, prioritizing Oracle HTTP Server, Fusion Middleware, E-Business Suite, PeopleSoft, and Identity Manager instances exposed to the internet.
- Verify the PeopleSoft out-of-band fix: Confirm the June 11 patch for CVE-2026-35273 was applied to every PeopleTools instance. If it wasn’t, do not simply patch and move on. Assume compromise and begin incident response first: check for unauthorized persistence mechanisms, review authentication logs since late May, and audit for unexpected admin accounts before applying the permanent fix.
- Sequence by exposure: Internet-facing instances of HTTP Server, WebLogic Proxy Plug-in, and PeopleSoft should be patched ahead of internal-only deployments, even where CVSS scores are similar across products.
- Re-check January 2026 CPU status: Environments that applied only the January fix for the WebLogic Proxy Plug-in family remain exposed to CVE-2026-21962. Confirm that both patch cycles are complete.
- Review logs for suspicious activity: Audit web server and application logs for requests targeting the endpoints and components named above, going back to at least late May, given the PeopleSoft campaign’s timeline.
- Restrict administrative surface: Limit public access to admin interfaces and management consoles across Fusion Middleware, WebLogic, and Identity Manager until patches are confirmed.
- Track Oracle’s ongoing advisories: Given the size of this CPU, third-party researchers and Oracle itself are still publishing analysis. Revisit patch status regularly over the coming weeks to stay current as new findings emerge.
AppTrana WAAP Coverage for the Oracle July 2026 CPU
AppTrana customers are protected against exploitation attempts targeting the critical Oracle web vulnerabilities addressed in this CPU, including CVE-2026-35278, CVE-2026-35273, CVE-2026-21962, CVE-2026-60365, CVE-2026-60880, CVE-2026-60773, CVE-2026-62549, CVE-2026-35268, and CVE-2026-21992.
By inspecting and filtering malicious HTTP requests at the edge, AppTrana helps block exploitation attempts before they reach vulnerable Oracle applications, giving organizations protected time to validate and deploy Oracle’s security updates.