Oracle released its largest security update on record in July 2026, issuing 1,449 patches that collectively fix more than 1,200 CVEs across 30 product families. The unprecedented scale—3.7 times Oracle’s usual quarterly volume from 2021-2025—signals the mounting pressure enterprises face keeping their software secure in an era of AI-powered vulnerability discovery.

The July 2026 Critical Patch Update nearly tripled the company’s previous all-time record of 520 patches, set in April 2022. Among the vulnerabilities fixed, 600 were remotely exploitable without authentication, a particularly dangerous category that gives attackers a direct path into systems.
Fusion Middleware Under Assault
Fusion Middleware bore the brunt of the vulnerability load, with 355 security flaws including 219 remotely exploitable weaknesses. Ten of those scored a perfect 10.0 on the CVSS vulnerability severity scale, the highest possible rating.
High severity vulnerabilities made up 52.7% of the patch set, while critical severity patches accounted for 18%. Medium-severity fixes rounded out 24.7%.
AI Likely Behind Flood of Findings
Security researchers believe artificial intelligence identified the vast majority of these vulnerabilities. AI systems can scan code at machine speed, find subtle flaws humans miss, and—as the security industry has learned—enable attackers to weaponize those same discoveries almost instantly.
The patch surge underscores a hard truth: as AI gets better at finding bugs, the gap between discovery and attack narrows, making rapid patching the only reliable defense.
Enterprises need to treat this patch release as urgent, not routine. The sheer volume and severity signal that AI-powered attack capabilities are evolving faster than traditional patch schedules can handle.



