Oracle's First Monthly Security Patch Addresses 77 Vulnerabilities
Crispy enough to crunch, soft enough to enjoy. A good bake.
Summary
Oracle released its first monthly Critical Security Patch Update (CSPU) supplement, addressing 77 vulnerabilities across Database Server, REST Data Services, Communications, E-Business Suite, and Hospitality Applications. About a dozen of these are critical-severity issues. The CSPU program supplements the quarterly CPU releases by addressing high-priority security issues sooner. The May 2026 CSPU includes 12 patches for E-Business Suite, three of which are remotely exploitable without authentication. Additional CSPUs are scheduled for June, August, and September 2026.
Key quotes
· 3 pulledThe monthly CSPU supplements quarterly Critical Patch Update releases by addressing high-priority issues sooner.
The May 2026 CSPU covers Database Server, REST Data Services, Communications, E-Business Suite, and Hospitality Applications, totaling 77 vulnerabilities with about a dozen critical-severity issues.
E-Business Suite includes 12 patches, including three remotely exploitable without authentication.
You might also wanna read
libpng 1.6.51 Released with Security Fixes for Four Buffer Overflow Vulnerabilities
libpng 1.6.51 has been released to address four buffer overflow vulnerabilities discovered through fuzzing and security research. The releas
cPanel Issues Second Emergency Patch After Ransomware Attack Compromised 44,000 Servers
cPanel issued a second emergency security patch (TSR) on May 8, 2026, just ten days after a ransomware attack exploited CVE-2026-41940 to co
Critical GitHub Copilot Vulnerability Allowed Source Code and Secret Exfiltration
A critical vulnerability (CVSS 9.6) was discovered in GitHub Copilot Chat in June 2025 that allowed attackers to silently exfiltrate secrets
Google Project Zero Addresses the 'Patch Gap' in Vulnerability Disclosure
The article discusses Google Project Zero's updated vulnerability disclosure policy, the '90+30' model, introduced in 2021 to accelerate pat
Critical RCE vulnerability CVE-2026-3854 discovered in GitHub's internal git infrastructure
Wiz Research discovered a critical vulnerability (CVE-2026-3854) in GitHub's internal git infrastructure affecting both GitHub.com and GitHu
React Server Components Security Vulnerabilities: Denial of Service and Source Code Exposure Risks
The React team has disclosed critical security vulnerabilities in React Server Components affecting versions 19.0.0 through 19.2.3, includin
