<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/oracle-critical-security-patch-update-june-2026-oanshrtv4" -->

---
title: Oracle Critical Security Patch Update June 2026 | daily.dev
description: Oracle released its June 2026 Critical Security Patch Update (CSPU), addressing 243 CVEs across 245 security patches in 11 product families. Nearly half...
canonical: https://daily.dev/posts/oracle-critical-security-patch-update-june-2026-oanshrtv4
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Oracle Critical Security Patch Update June 2026 | daily.dev
og:description: Oracle released its June 2026 Critical Security Patch Update (CSPU), addressing 243 CVEs across 245 security patches in 11 product families. Nearly half...
og:url: https://daily.dev/posts/oracle-critical-security-patch-update-june-2026-oanshrtv4
og:image: https://api.daily.dev/og/posts/OANSHrtv4.png
og:image:alt: Oracle Critical Security Patch Update June 2026
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Oracle Critical Security Patch Update June 2026

**[Tenable Blog](https://daily.dev/sources/tenable-blog)** · 3 min read · 0 upvotes · 0 comments

## Summary

Oracle released its June 2026 Critical Security Patch Update (CSPU), addressing 243 CVEs across 245 security patches in 11 product families. Nearly half (49.8%) of patches are rated critical severity. Oracle Fusion Middleware received the most patches at 106 (43.3%), followed by Oracle E-Business Suite at 55. A notable highlight is CVE-2026-35273, a zero-day remote code execution vulnerability in Oracle PeopleSoft Enterprise PeopleTools that was actively exploited in the wild by the extortion group ShinyHunters (UNC6240), affecting over 100 organizations globally — 68% of which were in the higher education sector. Organizations are urged to apply all relevant patches immediately.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.tenable.com/blog/oracle-june-2026-critical-security-patch-update-addresses-243-cves-cve-2026-35273>

## Questions this post answers

### What is CVE-2026-35273 and has it been exploited in the wild?

CVE-2026-35273 is a remote code execution vulnerability in Oracle PeopleSoft Enterprise PeopleTools, patched via an out-of-band Oracle Security Alert Advisory on June 10, 2026. Google Threat Intelligence Group and Mandiant confirmed it was exploited as a zero-day by the extortion group ShinyHunters (UNC6240), affecting over 100 organizations globally, 68% of them in US higher education.

_Teams tracking exploited Oracle vulnerabilities can follow patch guidance and threat updates on daily.dev._

### How many CVEs does Oracle's June 2026 Critical Security Patch Update fix?

Oracle's June 2026 Critical Security Patch Update fixes 243 unique CVEs across 245 security updates spanning 11 product families, with 122 patches (49.8%) rated critical severity. Oracle Fusion Middleware received the most patches at 106 (43.3%), followed by Oracle E-Business Suite at 55 patches (22.4%).

_Admins scheduling Oracle patch cycles can track CSPU breakdowns like this on daily.dev._

### What is Oracle's new Critical Security Patch Update (CSPU) release cycle?

Starting in May 2026, Oracle introduced monthly Critical Security Patch Updates (CSPUs) that sit between its larger quarterly Critical Patch Updates (CPUs), addressing a focused set of high-severity issues on a faster cadence. The June 2026 release is the second CSPU under this new schedule.

_Security teams adjusting patch cadence to Oracle's new schedule can keep up via daily.dev._

## Similar posts on daily.dev

- [Oracle Critical Security Patch Update May 2026](https://daily.dev/posts/oracle-critical-security-patch-update-may-2026-zxlrz2jvd) · Tenable Blog · 0 upvotes · 0 comments
- [Oracle releases 245 new security patches, all rated ‘high-priority security’](https://daily.dev/posts/oracle-releases-245-new-security-patches-all-rated-high-priority-security--aiut2jpue) · CSO Online · 1 upvotes · 0 comments
- [Oracle Critical Security Patch Update August 2026](https://daily.dev/posts/oracle-critical-security-patch-update-august-2026-r6ygfhpmb) · Tenable Blog · 0 upvotes · 0 comments
- [Oracle April 2026 Critical Patch Update Addresses 241 CVEs](https://daily.dev/posts/oracle-april-2026-critical-patch-update-addresses-241-cves-d4hmqt3bg) · Security Boulevard · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#oracle](https://daily.dev/tags/oracle)

[View this post on daily.dev](https://daily.dev/posts/oracle-critical-security-patch-update-june-2026-oanshrtv4)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Oracle Critical Security Patch Update June 2026","url":"https://daily.dev/posts/oracle-critical-security-patch-update-june-2026-oanshrtv4","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/oracle-critical-security-patch-update-june-2026-oanshrtv4"},"datePublished":"2026-06-18T09:46:48.297Z","dateModified":"2026-09-13T19:36:02.446Z","description":"Oracle released its June 2026 Critical Security Patch Update (CSPU), addressing 243 CVEs across 245 security patches in 11 product families. Nearly half...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/b2e0e794b08883b0787072326c01d5a5?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/b2e0e794b08883b0787072326c01d5a5?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Tenable Blog","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Tenable Blog","logo":"https://media.daily.dev/image/upload/s--B6GAvw3H--/f_auto,q_auto/v1780213271/logos/tenable-blog?_a=BAMAMiWQ0","url":"https://daily.dev/sources/tenable-blog"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/oracle-critical-security-patch-update-june-2026-oanshrtv4","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,oracle","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Tenable Blog","item":"https://daily.dev/sources/tenable-blog"},{"@type":"ListItem","position":3,"name":"Oracle Critical Security Patch Update June 2026"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/oracle-critical-security-patch-update-june-2026-oanshrtv4#faq","mainEntity":[{"@type":"Question","name":"What is CVE-2026-35273 and has it been exploited in the wild?","acceptedAnswer":{"@type":"Answer","text":"CVE-2026-35273 is a remote code execution vulnerability in Oracle PeopleSoft Enterprise PeopleTools, patched via an out-of-band Oracle Security Alert Advisory on June 10, 2026. Google Threat Intelligence Group and Mandiant confirmed it was exploited as a zero-day by the extortion group ShinyHunters (UNC6240), affecting over 100 organizations globally, 68% of them in US higher education. Teams tracking exploited Oracle vulnerabilities can follow patch guidance and threat updates on daily.dev."}},{"@type":"Question","name":"How many CVEs does Oracle's June 2026 Critical Security Patch Update fix?","acceptedAnswer":{"@type":"Answer","text":"Oracle's June 2026 Critical Security Patch Update fixes 243 unique CVEs across 245 security updates spanning 11 product families, with 122 patches (49.8%) rated critical severity. Oracle Fusion Middleware received the most patches at 106 (43.3%), followed by Oracle E-Business Suite at 55 patches (22.4%). Admins scheduling Oracle patch cycles can track CSPU breakdowns like this on daily.dev."}},{"@type":"Question","name":"What is Oracle's new Critical Security Patch Update (CSPU) release cycle?","acceptedAnswer":{"@type":"Answer","text":"Starting in May 2026, Oracle introduced monthly Critical Security Patch Updates (CSPUs) that sit between its larger quarterly Critical Patch Updates (CPUs), addressing a focused set of high-severity issues on a faster cadence. The June 2026 release is the second CSPU under this new schedule. Security teams adjusting patch cadence to Oracle's new schedule can keep up via daily.dev."}}]}
```

