Thursday , July 23 2026
Oracle

Oracle fixes 1,400+ vulnerabilities; critical flaws threaten enterprise servers

Oracle has fixed over 1,400 security holes in its July 2026 Critical Patch Update (CPU). Most of these flaws were probably found by artificial intelligence. According to Oracle, the latest quarterly CPU includes 1,449 security patches, addressing 1,434 unique CVEs across 334 products.

Vulnerabilities have been fixed in products like Database Server, APEX, Autonomous Health Framework, Essbase, Global Lifecycle Management, GoldenGate, NoSQL Database, Spatial Studio, SQL Developer, TimesTen In-Memory Database, Application Testing Suite, Commerce, Communications, Construction and Engineering, and E-Business Suite.

Anthropic Unveils Claude Security Plugin for Code Flaw Scanning

Anthropic launched the Claude Security plugin in beta. This tool uses AI to find serious security flaws in Claude Code....
Read More
Anthropic Unveils Claude Security Plugin for Code Flaw Scanning

Apple, ASUS Router, Meta, Windmill & Ubuntu Patch Critical Security Flaws

ASUS has put out important security updates for a serious router flaw. This issue could let remote hackers run any...
Read More
Apple, ASUS Router, Meta, Windmill & Ubuntu Patch Critical Security Flaws

SolarWinds Patches 15 Critical Serv-U Flaws

SolarWinds has shared important security updates for its Serv-U file transfer software. These updates fix 15 problems that could let...
Read More
SolarWinds Patches 15 Critical Serv-U Flaws

Oracle fixes 1,400+ vulnerabilities; critical flaws threaten enterprise servers

Oracle has fixed over 1,400 security holes in its July 2026 Critical Patch Update (CPU). Most of these flaws were...
Read More
Oracle fixes 1,400+ vulnerabilities; critical flaws threaten enterprise servers

Zimbra Patches 4 XSS and Critical SNMP Command Injection Flaws

Zimbra has launched updates to fix serious security flaws, including a command injection bug in the SNMP monitoring part. As...
Read More
Zimbra Patches 4 XSS and Critical SNMP Command Injection Flaws

Qilin ransomware gang exploiting critical Palo Alto VPN Flaw

The Qilin ransomware group is exploiting a flaw in PAN-OS GlobalProtect to break into victims' networks, says the cybersecurity firm...
Read More
Qilin ransomware gang exploiting critical Palo Alto VPN Flaw

“PentestCode” AI Agent Automating Penetration Testing with 18 Tools

A new free tool is adding AI helpers into security work. PentestCode is a version of OpenCode made just for...
Read More
“PentestCode” AI Agent Automating Penetration Testing with 18 Tools

CVE-2026-60137, CVE-2026-63030
Patch immediately! 2 high severity WordPress flaws found

The WordPress security team received reports about these flaws: CVE-2026-60137 : A facilitated SQL injection issue reported as a team...
Read More
CVE-2026-60137, CVE-2026-63030  Patch immediately! 2 high severity WordPress flaws found

Windows LegacyHive 0, AWS, Fortinet, TP-LINK multiple flaws got hackers attention

A Windows security flaw called LegacyHive (MSNightmare) misuses the User Profile Service. This allows local users to gain higher privileges,...
Read More
Windows LegacyHive 0, AWS, Fortinet, TP-LINK multiple flaws got hackers attention

CVE-2026-53412
Zoom Warns of critical account takeover Flaw via Network Access

Zoom has issued updates for a flaw in the Windows desktop client, known as CVE-2026-53412. This issue may allow an...
Read More
CVE-2026-53412  Zoom Warns of critical account takeover Flaw via Network Access

Security updates are also ready for Enterprise Manager, Financial Services Apps, Food and Beverage Apps, Fusion Middleware, Analytics, HealthCare Apps, Hospitality Apps, Java SE, JD Edwards, MySQL, PeopleSoft, Retail Apps, Siebel CRM, Supply Chain, Systems, Utilities Apps, and Virtualization.

About 600 patches fix flaws that can be attacked from far away without needing a login. Many security issues have been given a high severity rating.

The highest numbers of vulnerabilities were patched in E-Business Suite (410), Fusion Middleware (355), Communications (168), and PeopleSoft (84).

Most of the new security problems were found inside the company, probably with help from AI. Only a small number of issues were discovered by outside researchers.

Oracle said earlier this year that it can use advanced AI systems like Anthropic’s Claude Mythos and OpenAI’s best models. They are using these systems to find and fix security issues faster and better.

The company said it is using this AI-based security work on its own software and services, Oracle Health, and the open-source parts it creates and depends on.

Organizations need to apply the latest updates quickly because hackers often take advantage of weaknesses in Oracle products. For example, there was a PeopleSoft zero-day attack and a new fix for an EBS weakness.

For security teams, this July CPU is a clear signal to:

Prioritize patching of internet‑facing Oracle assets and high‑privilege application tiers.
Integrate Oracle’s monthly CSPUs and quarterly CPUs into vulnerability management SLAs.
Track AI‑discovered CVEs and map them to MITRE ATT&CK techniques to understand likely attack paths.
Use compensating controls (WAF, network segmentation, virtual patching) where immediate patching is operationally difficult.

Check Also

Qilin

Qilin ransomware gang exploiting critical Palo Alto VPN Flaw

The Qilin ransomware group is exploiting a flaw in PAN-OS GlobalProtect to break into victims’ …