Oracle rolls out monthly security patch updates
Overview
Oracle has announced a significant change to its security update process, set to take effect in May 2026. The company will introduce a monthly Critical Security Patch Update (CSPU) that aims to deliver smaller, more targeted fixes for security vulnerabilities. This new approach will complement the existing quarterly Critical Patch Updates (CPUs), which will continue to include all fixes from previous CSPUs. The shift to monthly updates is designed to make it easier for organizations to apply critical security fixes promptly. This change is particularly relevant for companies managing their own deployments, as it emphasizes the need for timely updates in an ever-evolving cybersecurity landscape.
Key Takeaways
- Affected Systems: Oracle products, customer-managed deployments
- Action Required: Implement monthly Critical Security Patch Updates starting May 2026 and continue using quarterly Critical Patch Updates.
- Timeline: Disclosed on October 2023
Original Article Summary
Oracle is changing how its security fixes are delivered: starting in May 2026, there will be a monthly Critical Security Patch Update. “Each [monthly] CSPU is smaller and more focused, making it easier to apply critical fixes quickly [to customer-managed deployments],” Oracle says. Quarterly Critical Patch Updates (CPUs) remain in place and will continue to include all fixes released in prior CSPUs. Managing security across environments Protections and updates are applied automatically and continuously in … More → The post Oracle rolls out monthly security patch updates appeared first on Help Net Security.
Impact
Oracle products, customer-managed deployments
Exploitation Status
No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.
Timeline
Disclosed on October 2023
Remediation
Implement monthly Critical Security Patch Updates starting May 2026 and continue using quarterly Critical Patch Updates.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Patch, Update, Critical, and 1 more.