Oracle has released 943 security patches across Database, E-Business Suite, WebLogic, Java, MySQL and other products. Here is how to prioritise affected systems.
- On 18 August 2026, Oracle published 943 new security patches across a broad set of enterprise products.
- Several product groups include vulnerabilities that may be remotely exploitable without credentials, including Fusion Middleware, E-Business Suite, Oracle Commerce, Database, Java and MySQL.
- Oracle does not say the flaws in this update are being actively exploited; organisations should prioritise by product, version and exposure rather than the headline patch count alone.
What happened, who is affected and what should teams do now?
On 18 August 2026, Oracle published its August Critical Security Patch Update with 943 new security patches. The scope includes Oracle Database, E-Business Suite, Fusion Middleware and WebLogic, as well as Java, MySQL, Oracle Commerce, PeopleSoft, Hyperion and other products.
Organisations running affected on-premises Oracle products should check the exact product, version and exposed services. The update is significant because many vulnerabilities may be remotely exploitable without credentials. Oracle does not, however, state that the flaws in this release are being actively exploited.
The immediate task is to inventory relevant systems, compare deployed versions with Oracle’s matrices, obtain the correct patches through My Oracle Support and test them outside production before rollout.
The first task is not to patch 943 items at once; it is to identify which affected systems the organisation actually runs and exposes.
What the number 943 does — and does not — mean
The figure represents patches across many product families, not 943 attacks in progress. The same underlying vulnerability may also appear in more than one matrix when a component is reused.
Priority should therefore reflect real exposure. An internet-facing service with a pre-authentication flaw will usually deserve attention before an isolated internal system, even when both are covered by the advisory.
- Oracle Fusion Middleware: 262 patches; Oracle says 182 vulnerabilities may be remotely exploitable without authentication.
- Oracle E-Business Suite: 120 patches; 27 may be remotely exploitable without authentication.
- Oracle Commerce: 66 patches; 47 may be remotely exploitable without authentication.
- Oracle Database Server: 6 new patches; 4 may be remotely exploitable without authentication.
- Oracle MySQL: 9 patches; 5 may be remotely exploitable without authentication.
- Oracle Java SE: 5 patches; 4 may be remotely exploitable without authentication.
WebLogic and middleware deserve close review
Within Fusion Middleware, Oracle lists several high-severity WebLogic Server issues. CVE-2026-60698, CVE-2026-60977, CVE-2026-60672 and CVE-2026-60696 each carry a CVSS score of 9.8 and are marked as remotely exploitable without authentication in affected versions.
CVSS is a technical severity score. A 9.8 rating is very high, but remediation priority still depends on whether the exact version is deployed, whether the relevant protocol is enabled and whether the service is reachable from outside the trusted network.
For E-Business Suite, Oracle notes that exposure also depends on the accompanying Database and Fusion Middleware versions. Patching only the application layer may leave the underlying stack incomplete.
The advisory does not confirm active exploitation
Oracle says it has periodically received reports of attempts to exploit vulnerabilities for which patches already existed, including successful attacks where customers had not applied available updates. That history supports prompt patching.
The 18 August advisory does not say that the newly addressed flaws are being exploited in the wild. Friday Works therefore does not describe this release as an active attack campaign. Any later evidence from Oracle or an authoritative vulnerability catalogue should be treated as a separate update.
A practical 24–72 hour checklist
The goal is to reduce exposure without destabilising critical systems. Oracle warns that protocol blocks or privilege removal may break application functionality, so temporary controls should be tested as well.
- Inventory Oracle Database, WebLogic, E-Business Suite, Java, MySQL and other Oracle products, including legacy and non-production environments.
- Record versions, business owners, network ports, protocols and reachability from the internet or partner networks.
- Match deployed versions against Oracle’s affected-version and Patch Availability documents; do not infer exposure from the product name alone.
- Prioritise externally reachable services, pre-authentication flaws and issues with high confidentiality, integrity or availability impact.
- Back up, prepare rollback, test outside production and exercise critical business flows before broad rollout.
- After patching, verify the deployed version, service health, integrations and logs, and retain completion evidence.
If patching cannot happen immediately
Oracle suggests blocking protocols required for an attack or removing unnecessary privileges as temporary risk-reduction measures. These controls do not fix the underlying vulnerability and may interrupt business functions.
Teams can restrict access through network controls or VPN, disable unused services, review privileged accounts and increase log monitoring while waiting. Every temporary measure should have an owner, an expiry date and a plan to replace it with the official patch.
Where Friday Works can help
Friday Works does not replace Oracle Support or specialist product administrators. We can help inventory related web, web app and API exposure; review access controls; examine application-level configuration; and retest integration paths after the operating team applies vendor patches.
For systems with several web, API and integration layers, a clearly scoped assessment helps separate vendor-product issues from application configuration and business-logic risks.
FAQ
Frequently asked questions
Are organisations that do not use Oracle affected?
Not directly. The advisory applies to the Oracle products and versions listed in the affected-product matrices. Teams should first confirm what is actually deployed.
Do 943 patches mean 943 vulnerabilities are under active attack?
No. The number covers patches across many product families. Oracle does not state that the newly addressed flaws are being actively exploited.
Can a network block replace patching?
Protocol blocks or privilege reduction can lower exposure temporarily, but they do not fix the underlying flaw and may break functionality. Oracle still recommends applying official patches promptly.
References
Sources used in this guide
We prioritise official guidance and primary technical sources. Visit each source for full context and the latest updates.

