Oracle’s August Patch Map: 943 Fixes, 182 Unauthenticated Middleware Paths
Oracle’s August 2026 Critical Security Patch Update is less a conventional patch bundle than a map of enterprise blast radius. It contains 943 new security patches across databases, middleware, business applications, identity systems, communications products, Java, MySQL, and other product families.
The number that should stop defenders is not 943 by itself. It is the concentration of unauthenticated attack paths inside systems that often sit behind an organisation’s most trusted business processes. Oracle Fusion Middleware accounts for 262 new patches, and Oracle says 182 of those vulnerabilities may be remotely exploitable without authentication.
The middleware layer carries the largest immediate exposure
Oracle’s official risk matrix lists a maximum-severity issue in the LDAP server used by Oracle Internet Directory. CVE-2026-61241 has a CVSS score of 10.0, requires no credentials or user interaction, and can affect confidentiality, integrity, and availability across Oracle Internet Directory 12.2.1.4.0 and 14.1.2.1.0.
Helidon’s Imperative Web Server also appears near the top of the matrix. CVE-2026-73930 is scored 9.9 and is remotely exploitable without authentication over HTTP in version 4.5.3. The middleware list also includes high-impact issues across Identity Manager, Access Manager, Managed File Transfer, Reports Developer, WebCenter, and WebLogic.
This is why the “182” figure matters operationally. Middleware tends to be shared. One exposed identity, directory, web-service, or integration component can sit in front of several applications and business units, turning a product-specific flaw into an estate-wide trust failure.
E-Business Suite adds two unauthenticated 9.8 paths
Oracle E-Business Suite receives 120 new security patches, 27 of which may be remotely exploitable without credentials. Two top-scoring entries affect core business workflows across supported E-Business Suite releases 12.2.3 through 12.2.15.
- CVE-2026-60782, CVSS 9.8, affects Oracle Payments File Transmission over HTTP. Oracle’s vector indicates low complexity, no privileges, no user interaction, and high impact to confidentiality, integrity, and availability.
- CVE-2026-70926, CVSS 9.8, affects the Oracle Workflow Notification Mailer over SMTP under the same no-credential, no-interaction conditions.
E-Business Suite customers also need to account for the Oracle Database and Fusion Middleware components beneath the application. Oracle explicitly warns that those underlying patches are not repeated in the E-Business Suite matrix, even though the exposure can carry into the suite. Patching only the application-level entries can therefore leave a material gap.
Database risk is smaller in count, not necessarily in consequence
The database product family receives 17 new patches: six for Oracle Database Server, seven for Autonomous Health Framework, and four for Essbase. Four of the six Database Server vulnerabilities may be remotely exploited without authentication.
CVE-2026-71063 affects Portable Clusterware over TLS and carries a CVSS score of 9.6. Oracle classifies the attack vector as adjacent network, not general internet reachability, but a successful exploit can still produce high confidentiality, integrity, and availability impact across supported 19c, 21c, and 23ai release ranges.
A revision changed one database boundary
Oracle first released the advisory on 18 August and revised it on 20 August. The revision corrected the affected range for CVE-2026-71062 from 23.4.0 through 23.26.3 to 23.4.0 through 23.26.2. Oracle supplied publication dates but no times. Teams that imported the first risk matrix should refresh their inventory rather than rely on the original version boundary.
What defenders should do now
- Map every affected Oracle product and component to its patch availability document. Do not treat 943 as one deployable update.
- Prioritise unauthenticated network paths, especially LDAP, HTTP, SMTP, T3, IIOP, and externally reachable identity or integration services.
- For E-Business Suite, include its Database and Fusion Middleware dependencies in the same remediation plan.
- Refresh asset and version data against the 20 August revision.
- Use temporary protocol restrictions or privilege reductions only as risk controls while patching. Oracle warns that these measures can break functionality and do not fix the underlying defects.
Oracle says the Critical Security Patch Update format is intended to deliver focused high-priority fixes between quarterly Critical Patch Updates. It also notes that attackers continue to target previously patched Oracle vulnerabilities when customers fall behind. That is a general warning, not confirmation that the August flaws are under active exploitation, but the update’s unauthenticated reach makes delay an expensive assumption.


