<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/oracle-issues-critical-patches-for-database-server-fusion-middleware-x1dra3itq" -->

---
title: Oracle issues critical patches for Database Server,...
description: Oracle&#x27;s July 2026 Critical Patch Update is its largest ever, delivering 1,449 security patches across 32 product families. Fusion Middleware was the hardest...
canonical: https://daily.dev/posts/oracle-issues-critical-patches-for-database-server-fusion-middleware-x1dra3itq
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Oracle issues critical patches for Database Server, Fusion Middleware | daily.dev
og:description: Oracle&#x27;s July 2026 Critical Patch Update is its largest ever, delivering 1,449 security patches across 32 product families. Fusion Middleware was the hardest...
og:url: https://daily.dev/posts/oracle-issues-critical-patches-for-database-server-fusion-middleware-x1dra3itq
og:image: https://api.daily.dev/og/posts/x1drA3iTq.png
og:image:alt: Oracle issues critical patches for Database Server, Fusion Middleware
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Oracle issues critical patches for Database Server, Fusion Middleware

**[CSO Online](https://daily.dev/sources/csoonline)** · 5 min read · 1 upvotes · 0 comments

## Summary

Oracle's July 2026 Critical Patch Update is its largest ever, delivering 1,449 security patches across 32 product families. Fusion Middleware was the hardest hit, with 355 vulnerabilities patched — 219 remotely exploitable without authentication and ten scoring a perfect 10.0 CVSS. Oracle Database Server received patches for CVE-2026-61211 (CVSS 9.9), a DBMS_CLOUD flaw enabling full RDBMS takeover by low-privileged attackers, and CVE-2026-47040 in Oracle Net Services. Security experts recommend a tiered response: address internet-reachable and reported vulnerabilities within 72 hours, trusted core systems within 10 days, and the rest before the October release. The update also highlights the operational complexity of enterprise patching, with Oracle now running both quarterly and monthly patch cadences simultaneously.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.csoonline.com/article/4200184/oracles-july-update-fixes-ten-10-0-vulnerabilities-in-fusion-middleware.html>

## Questions this post answers

### What is CVE-2026-61211 and which Oracle Database versions does it affect?

CVE-2026-61211 is a critical vulnerability (CVSS 9.9) in the RDBMS component's DBMS_CLOUD package, allowing a low-privileged attacker with Execute DBMS_CLOUD privilege and network access via Oracle Net to compromise and potentially take over the RDBMS. It affects Database Server versions 19.3 through 19.31 and 23.4.0 through 23.26.2, patched in Oracle's July 2026 Critical Patch Update.

_Teams tracking Oracle Database CVEs and patch windows can follow advisories like this on daily.dev._

### How many vulnerabilities did Oracle's July 2026 Critical Patch Update fix and how does that compare to previous quarters?

Oracle's July 2026 Critical Patch Update contains 1,449 new security patches across 32 product families, its largest release ever. This compares to 481 patches in April 2026 and 309 a year earlier, a volume increase analysts say is outgrowing the operational capacity many organizations have to remediate them.

_Security teams sizing up patch backlogs can keep an eye on Oracle's release cadence via daily.dev._

### How many Fusion Middleware vulnerabilities were fixed in Oracle's July 2026 patch update and how severe were they?

355 security vulnerabilities in Fusion Middleware were patched, with 219 remotely exploitable without authentication and ten scoring a perfect 10.0 CVSS. Affected products include Oracle Data Integrator, Oracle Access Manager, Oracle HTTP Server, Oracle Platform Security for Java, Oracle WebCenter Content, Service Delivery Platform, and WebLogic Server Proxy Plug-in.

_Anyone triaging Fusion Middleware exposure can track advisories like this through daily.dev._

## Similar posts on daily.dev

- [Oracle July 2026 Critical Patch Update 1235 CVEs](https://daily.dev/posts/oracle-july-2026-critical-patch-update-1235-cves-irkciptx1) · Tenable Blog · 0 upvotes · 0 comments
- [Oracle Critical Security Patch Update June 2026](https://daily.dev/posts/oracle-critical-security-patch-update-june-2026-oanshrtv4) · Tenable Blog · 0 upvotes · 0 comments
- [Oracle releases 245 new security patches, all rated ‘high-priority security’](https://daily.dev/posts/oracle-releases-245-new-security-patches-all-rated-high-priority-security--aiut2jpue) · CSO Online · 1 upvotes · 0 comments
- [Oracle April 2026 Critical Patch Update Addresses 241 CVEs](https://daily.dev/posts/oracle-april-2026-critical-patch-update-addresses-241-cves-d4hmqt3bg) · Security Boulevard · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#oracle](https://daily.dev/tags/oracle)

[View this post on daily.dev](https://daily.dev/posts/oracle-issues-critical-patches-for-database-server-fusion-middleware-x1dra3itq)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Oracle issues critical patches for Database Server, Fusion Middleware","url":"https://daily.dev/posts/oracle-issues-critical-patches-for-database-server-fusion-middleware-x1dra3itq","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/oracle-issues-critical-patches-for-database-server-fusion-middleware-x1dra3itq"},"datePublished":"2026-07-22T18:15:36.166Z","dateModified":"2026-09-14T06:38:23.063Z","description":"Oracle's July 2026 Critical Patch Update is its largest ever, delivering 1,449 security patches across 32 product families. Fusion Middleware was the hardest...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/6d1a2c626401f9f003d897c52da97455?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/6d1a2c626401f9f003d897c52da97455?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"CSO Online","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"CSO Online","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/98667e4b5cac46cf9c470819c6cf71cd","url":"https://daily.dev/sources/csoonline"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/oracle-issues-critical-patches-for-database-server-fusion-middleware-x1dra3itq","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,oracle","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"CSO Online","item":"https://daily.dev/sources/csoonline"},{"@type":"ListItem","position":3,"name":"Oracle issues critical patches for Database Server, Fusion Middleware"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/oracle-issues-critical-patches-for-database-server-fusion-middleware-x1dra3itq#faq","mainEntity":[{"@type":"Question","name":"What is CVE-2026-61211 and which Oracle Database versions does it affect?","acceptedAnswer":{"@type":"Answer","text":"CVE-2026-61211 is a critical vulnerability (CVSS 9.9) in the RDBMS component's DBMS_CLOUD package, allowing a low-privileged attacker with Execute DBMS_CLOUD privilege and network access via Oracle Net to compromise and potentially take over the RDBMS. It affects Database Server versions 19.3 through 19.31 and 23.4.0 through 23.26.2, patched in Oracle's July 2026 Critical Patch Update. Teams tracking Oracle Database CVEs and patch windows can follow advisories like this on daily.dev."}},{"@type":"Question","name":"How many vulnerabilities did Oracle's July 2026 Critical Patch Update fix and how does that compare to previous quarters?","acceptedAnswer":{"@type":"Answer","text":"Oracle's July 2026 Critical Patch Update contains 1,449 new security patches across 32 product families, its largest release ever. This compares to 481 patches in April 2026 and 309 a year earlier, a volume increase analysts say is outgrowing the operational capacity many organizations have to remediate them. Security teams sizing up patch backlogs can keep an eye on Oracle's release cadence via daily.dev."}},{"@type":"Question","name":"How many Fusion Middleware vulnerabilities were fixed in Oracle's July 2026 patch update and how severe were they?","acceptedAnswer":{"@type":"Answer","text":"355 security vulnerabilities in Fusion Middleware were patched, with 219 remotely exploitable without authentication and ten scoring a perfect 10.0 CVSS. Affected products include Oracle Data Integrator, Oracle Access Manager, Oracle HTTP Server, Oracle Platform Security for Java, Oracle WebCenter Content, Service Delivery Platform, and WebLogic Server Proxy Plug-in. Anyone triaging Fusion Middleware exposure can track advisories like this through daily.dev."}}]}
```

