Vendor Security Posture Report Card: Oracle - Q2 2026
Explore Oracle's Q2 2026 security posture, including disclosed vulnerabilities, critical CVEs, security updates, patch management trends, exploitation risks, and key recommendations for enterprise security teams.
Vendor Security Posture Report Card: Oracle - Q2 2026
Reporting period: Q2 2026 (April 1 to June 30, 2026), covering Fusion Middleware, E-Business Suite, PeopleSoft, JD Edwards, Database, MySQL, and Oracle's other on-premises product families.
Vendor Summary
| Field | Notes |
|---|---|
| Vendor Name | Oracle |
| Product Lines Covered | Oracle's customer-managed (on-premises) product families covered by its security releases, including Fusion Middleware (WebLogic, HTTP Server, Identity Manager), E-Business Suite, PeopleSoft, JD Edwards, Database, MySQL, Communications, and Financial Services Applications |
| Reporting Period | Q2 2026 (April 1 to June 30, 2026) |
| Overall Posture Rating | Concerning |
| Prior Period Rating | Unavailable (first report card for this vendor) |
| Total CVEs Disclosed (Period) | About 520 unique CVEs, delivered as roughly 765 security patches across the April quarterly update, the May and June monthly updates, and one out-of-band alert |
| Critical and High Severity Count | Unique-CVE Critical and High counts are unavailable. At patch level, 167 patches were rated Critical (CVSS 9.0 or higher) and roughly 343 were rated High; these patch counts cannot be used as a deduplicated CVE severity distribution. |
| CVEs With Confirmed In-the-Wild Exploitation | 2 CVEs published in the period are listed in the KEV catalog as of writing (CVE-2026-35273 and CVE-2026-46817); at least 2 Oracle CVEs were added to the catalog during the quarter |
Rating Scale Reference
The rating scale applied consistently across every report card in this series, so that ratings remain comparable from one vendor and one period to the next:
| Rating | Criteria |
|---|---|
| Strong | Disclosure volume and severity trend stable or improving, advisories timely and complete, no unpatched critical exposure at time of writing. |
| Adequate | Posture broadly sound with isolated gaps, such as a delayed patch cycle or an incomplete advisory, that do not indicate a systemic pattern. |
| Needs Improvement | Recurring gaps across the period: repeated delayed patches, incomplete disclosures, or a rising severity trend. |
| Concerning | Evidence of a systemic issue: sustained critical exposure, exploitation preceding a patch, or a pattern of incomplete or delayed disclosure. |
This section is included in full on every post, unchanged, so the scale is never assumed to be self-evident.
Introduction
This report card assesses Oracle's security posture for the second quarter of 2026 across its on-premises enterprise software. Oracle receives an overall rating of Concerning. The decisive factor is exploitation of the PeopleSoft vulnerability before a fix was available. A further concern is the reported severity trend: the combined patch count rose relative to Q1 under an expanded release schedule, and the patch-level Critical share climbed from about 7 percent in April to about 50 percent in June, alongside an exploited PeopleSoft zero-day.
Scope and Methodology
This assessment covers the four security releases Oracle published in the period: the quarterly Critical Patch Update on April 21, the first two monthly Critical Security Patch Updates on May 28 and June 16, and an out-of-band Security Alert for CVE-2026-35273 on June 10. It also draws on KEV catalog listings dated between April 1 and June 30, plus later listings of CVEs first published in the period.
- Included: all product families named in those four releases, which cover Oracle's customer-managed software.
- Excluded: Oracle-managed cloud services, which receive updates automatically without customer action, and Oracle Linux errata.
- Data sources: Oracle's published security advisories and risk matrices, CVE and NVD records, and KEV catalog listings.
Data limitations. Oracle counts security patches, and one vulnerability can appear in several products, so patch counts run higher than unique CVE counts. For April, Oracle's 481 patches correspond to about 241 unique CVE IDs, and other tallies of the same release give different figures. For June, Oracle's pre-release announcement listed 251 patches, while tallies of the final advisory put the figure at 245 patches and 243 CVEs. This post reports patches as Oracle states them and unique CVEs as tallied. High-severity counts for May and June are derived from published percentages and are approximate. The comparison to the prior period uses the January 2026 Critical Patch Update, which listed 337 patches; it is not a like-for-like comparison with the expanded Q2 release schedule.
Vulnerability Disclosure Volume and Trend
Oracle disclosed about 520 unique CVEs in Q2, delivered as roughly 765 security patches:
- April 21 (quarterly update): 481 patches across 28 product families, corresponding to about 241 unique CVEs.
- May 28 (first monthly update): 35 patches and 35 CVEs across five product families.
- June 10 (out-of-band alert): one CVE, CVE-2026-35273, in PeopleSoft PeopleTools.
- June 16 (second monthly update): about 250 patches and 243 unique CVEs across 11 product families.
For the prior period, the January 2026 quarterly update listed 337 patches, and Q1 contained no monthly updates because the monthly program began in May. The combined Q2 release patch count is roughly 430 higher than the January update (about 126 percent), but this is not a like-for-like measure of vulnerability growth because Q2 includes additional monthly and out-of-band releases. A large part of the difference comes from Oracle's introduction of monthly updates on top of the quarterly cycle; Oracle has said the change responds to AI-accelerated vulnerability discovery, and the June update alone carried about as many CVEs as the April quarterly update. Because quarterly updates remain cumulative and include earlier monthly fixes, counts across the two programs can overlap in later periods.
Severity Distribution Analysis
Oracle rates each patch with a CVSS score in its risk matrices, and patches scoring 9.0 or higher are Critical. The counts below are patch-level figures, not a deduplicated CVE-level Critical, High, Medium, and Low distribution as required by the template. Complete unique-CVE severity counts are unavailable, so this section explicitly deviates from that requirement. The patch-level distribution shifted across the three scheduled releases:
- April: 34 Critical patches across 22 CVEs (7.1 percent), with High patches at 45.9 percent and Medium at 44.1 percent. More than 300 of the 481 patches addressed flaws that may be remotely exploitable without authentication.
- May: 11 Critical patches (31.4 percent) and High patches at 51.4 percent.
- June: 122 Critical patches (49.8 percent) and High patches at 42.4 percent, with Fusion Middleware accounting for 106 patches and E-Business Suite for about 55.
Across the quarter, 167 patches were Critical (about 22 percent of the total) and roughly 343 were High. The patch-level figures are weighted heavily toward higher severity, although this does not establish a like-for-like trend in distinct CVE severity. Part of that rise reflects the design of the monthly program, which is intended to carry the most urgent fixes, so the severity of the monthly releases is not directly comparable with the quarterly update.
Patch and Remediation Timeliness
Oracle meets the cadence it has publicly committed to. Quarterly updates arrive on the third Tuesday of January, April, July, and October, and the April 21 release was on schedule. Oracle announced on May 4 that monthly updates would begin on May 28 and then follow the third Tuesday of non-quarterly months, and the June 16 release met that date. Oracle also began publishing pre-release announcements the Thursday before each monthly update starting in June.
- Time to patch: Oracle generally publishes CVE details alongside available fixes in scheduled releases. The interval from discovery or private reporting to an available fix cannot be determined consistently from the reviewed advisories.
- Cadence improvement: the monthly updates provide more frequent opportunities for customers in customer-managed environments to deploy high-priority security fixes; they do not guarantee a maximum time to remediation.
- Lag case: CVE-2026-35273 in PeopleSoft PeopleTools was exploited as a zero-day from May 27, roughly two weeks before Oracle's June 10 out-of-band alert. The May 28 monthly update did not cover PeopleSoft.
- Day-one clarity: Oracle's June 10 alert provided mitigation and installation guidance; its June 16 monthly Critical Security Patch Update explicitly included patches for CVE-2026-35273. The alert does not clearly establish from its public text alone whether a complete fix was available on June 10.
Exploitation and Real-World Impact
Two CVEs published in Q2 are listed in the KEV catalog as of writing, and at least two Oracle CVEs were added to the catalog during the quarter itself:
- CVE-2026-35273 (PeopleSoft PeopleTools, CVSS 9.8): an unauthenticated remote code execution flaw in the Environment Management Hub, exploited in data-theft attacks by an extortion-focused group and added to the catalog on June 12, two days after Oracle's alert.
- CVE-2026-46817 (E-Business Suite, Oracle Payments, CVSS 9.8): fixed in the May 28 monthly update, with exploitation reported by late June (the exact first-exploitation date is not established), and added to the catalog on July 15, outside the quarter but for a CVE first published within it.
- CVE-2024-21182 (WebLogic Server): a flaw Oracle fixed in July 2024, added to the catalog on June 1, 2026, which shows that long-patched Oracle middleware flaws continue to be exploited.
Exploitation preceded a patch in one case, CVE-2026-35273. Against roughly 520 CVEs, two confirmed exploited Q2 CVEs represent about 0.4 per 100 advisory-listed CVEs; this observed fraction does not measure all exploitation, and both flaws are unauthenticated, critical, and in business applications that hold financial and personnel data.
Advisory and Communication Quality
Oracle's advisories are consistent and machine-friendly. Each release lists patches by product family, with risk matrices that give the component, CVE-ID, CVSS score and vector, attack vector, privileges required, and affected versions, and Oracle states how many flaws may be remotely exploitable without authentication. Oracle also gives advance notice of upcoming releases. The gaps this quarter concern depth and access:
- Advisory entries carry short, template descriptions, and patch availability details for the out-of-band alert sat behind a support-account login, which left outside parties uncertain about the status of the fix.
- Oracle counts patches rather than CVEs, and the same vulnerability can appear under several products, which produced widely different published totals for the April update (481 patches against roughly 241 CVEs).
- Oracle's June 10 alert was reported not to state exploitation status at publication, even though outside incident-response findings placed exploitation from May 27.
- Pre-release and final patch counts for the June update differed (251 against about 245), without an explanatory note in the sources reviewed.
Notable Incidents This Period
The PeopleSoft zero-day shaped this period's rating. CVE-2026-35273 was exploited for about two weeks before Oracle's out-of-band alert, affected PeopleTools 8.61 and 8.62, and was listed in the KEV catalog two days after the alert. The Oracle Payments flaw CVE-2026-46817, fixed in May and exploited in the weeks that followed, extended the pattern into the next quarter. A full technical analysis belongs in a dedicated post.
Historical Trend Comparison
Unavailable, as this is the first report card for Oracle. The Q1 2026 figures in the volume section serve as the baseline for the next edition, which will also be the first to include a full quarter of monthly updates.
Risk Context for Organizations
For organizations that rely on Oracle products, a Concerning rating supports accelerated patch prioritization rather than waiting for the next quarterly cycle. The monthly updates now carry the most urgent fixes, so treating them as out-of-band releases rather than as optional supplements is the realistic reading of this quarter. The June update, with roughly half of its patches rated Critical, is the clearest example.
Exposure is concentrated in internet-facing middleware and business applications, namely WebLogic and HTTP Server, PeopleSoft, and E-Business Suite. The gap between the May fix and the July listing for the Payments flaw shows that large ERP systems can remain unpatched for weeks while exploitation begins. Closer monitoring of KEV additions for Oracle products is warranted alongside the new monthly calendar.
Overall Posture Rating and Rationale
Oracle's Q2 2026 rating is . Three factors most influenced it:
- Rising volume and severity: patch volume more than doubled from Q1, and the Critical share rose from about 7 percent in April to about 50 percent in June (see Vulnerability Disclosure Volume and Trend and Severity Distribution Analysis).
- Exploitation of critical flaws: a PeopleSoft zero-day was exploited for about two weeks before its alert, and a Q2 E-Business Suite flaw was exploited after its fix (see Patch and Remediation Timeliness and Exploitation and Real-World Impact).
- Advisory depth and clarity: terse entries, gated patch details, and shifting patch counts leave customers to do much of the triage themselves (see Advisory and Communication Quality).
Oracle's reliable adherence to release dates and its launch of monthly security updates count in its favor. Nevertheless, exploitation of the PeopleSoft vulnerability before a fix was available directly meets the defined Concerning criterion; the high-severity patch-level findings provide additional context.
Key Takeaways
- Oracle's Q2 2026 rating is Concerning because the PeopleSoft vulnerability was exploited before a fix was available; the release inventory includes about 520 unique CVEs and roughly 765 security patches.
- The Q2 combined-release patch total was more than double January's 337 patches, but the release schedules differ; the patch-level Critical share rose from about 7 percent in April to about 50 percent in June.
- A PeopleSoft zero-day, CVE-2026-35273, was exploited for about two weeks before Oracle's June 10 out-of-band alert.
- An E-Business Suite flaw fixed on May 28, CVE-2026-46817, entered the KEV catalog on July 15; exploitation had been reported by late June, but its exact start date is not established.
- Oracle met every scheduled release date in the quarter and began monthly Critical Security Patch Updates on May 28.
Conclusion
Oracle's second quarter combined dependable release timing and a new monthly cadence with sharply rising severity and exploitation of critical flaws in its enterprise applications and middleware. These findings feed the ongoing vendor and compliance monitoring work behind this series. The Q3 2026 report card for Oracle is expected after the third-quarter reporting window closes.
Instantly Fix Risks with Saner Patch Management
Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.
It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.
Experience the fastest and most accurate patching software here.




