
Oracle released its June 2026 Critical Security Patch Update (CSPU) on June 16, 2026. This release addresses 243 unique CVEs through 245 individual security patches, spanning 11 Oracle product families. Of these, 122 patches carry a critical severity rating, accounting for roughly half the total release. We have break down what changed, product by product, so your team can prioritize patching based on what you actually run.
| Metric | Figure |
|---|---|
| Total security patches | 245 |
| Unique CVEs addressed | 243 |
| Product families covered | 11 |
| Critical severity patches | 122 (49.8% of total) |
| High severity patches | 42.4% of total |
This is Oracle’s second monthly Critical Security Patch Update since the program began in May 2026. CSPUs sit between Oracle’s larger quarterly Critical Patch Updates, delivering a faster, more focused release cadence for high-severity issues.
Source: Oracle Critical Security Patch Update Advisory, June 2026
Fusion Middleware received the largest share of this release: 106 patches, accounting for roughly 43% of the total. Of those, 53 vulnerabilities can be exploited remotely without authentication, meaning an attacker does not need valid credentials to attempt exploitation over the network.
Because Fusion Middleware underpins integrations and web-facing services across many Oracle deployments, this is the product family with the broadest potential exposure in this release. Organizations should confirm patch status here first if internet-facing Fusion Middleware components are in use.
E-Business Suite received 55 patches in this cycle, the second-largest share. Oracle’s own advisory notes that 6 of these vulnerabilities may be exploited remotely without authentication.
Oracle also states explicitly that E-Business Suite inherits vulnerabilities from the Oracle Database and Fusion Middleware components it depends on. Those underlying component patches are not listed separately in the EBS risk matrix, so applying the EBS-specific patches alone does not fully close this gap. Oracle recommends applying the June 2026 CSPU to the Database and Fusion Middleware layers underneath EBS as part of the same cycle.
PeopleSoft received 11 security patches this cycle. Seven of the eleven can be exploited remotely without user credentials.
One vulnerability in this release, CVE-2026-35273, affecting PeopleSoft Enterprise PeopleTools, has drawn additional attention outside of Oracle’s own advisory. Independent security researchers have reported observing the ShinyHunters threat group exploiting this flaw, with attacks reportedly affecting at least 100 organizations, concentrated in the education sector. Oracle has released a patch for this vulnerability. As of this writing, Oracle’s own public documentation does not explicitly confirm in-the-wild exploitation; that characterization comes from third-party security research, not from Oracle.
If your organization runs PeopleSoft, we recommend treating this specific patch as a priority within your June cycle rather than folding it into routine maintenance timing.
Enterprise Manager received 16 patches this cycle. Because Enterprise Manager environments include Oracle Database and Fusion Middleware components, the same inheritance logic that applies to E-Business Suite applies here: patching Enterprise Manager itself does not automatically patch the Database and Middleware layers it runs on. Oracle recommends reviewing those components as part of the same maintenance window.
MySQL received 8 security patches in this release. Of those, 4 can be exploited remotely without authentication. This is a smaller patch count relative to other product families in this cycle, but the proportion of remotely exploitable, unauthenticated issues (half) is worth noting for any internet-facing MySQL deployments.
| Question | Why it matters |
|---|---|
| Which of the five product families above are in your environment? | Not every organization runs all of them. Patch priority should follow your actual exposure, not the full Oracle list. |
| Have the June 2026 CSPU patches been applied to production and DR environments? | Long delays between release and deployment are one of the most common reasons known CVEs remain exploitable. |
| Are any Fusion Middleware, EBS, or MySQL services reachable from the internet? | Remotely exploitable vulnerabilities without authentication present much higher risk when services are internet facing. |
| If you run PeopleSoft, has CVE-2026-35273 been addressed? | Third party researchers have highlighted this vulnerability as a high priority because of reported exploitation attempts. |
| Have you verified the underlying Database and Fusion Middleware patch status for EBS or Enterprise Manager? | Oracle products inherit risk from underlying components, so product patch counts alone do not provide the complete picture. |
This summary is provided for informational purposes to help IT and security teams prioritize their own patch review. It is not a substitute for Oracle’s official advisory or a formal vulnerability assessment of your specific environment. Patch applicability, exploitability, and risk vary by version, configuration, and deployment topology. We recommend validating findings against Oracle’s official documentation before making patching decisions.
Need help assessing your Oracle environment’s patch status or planning a structured Oracle Security Health Check?
Contact RalanTech to talk through your specific Oracle footprint.