Oracle’s First Monthly Patches Resolve 77 Vulnerabilities

https://www.securityweek.com/wp-content/uploads/2024/01/Oracle.jpeg

Oracle has debuted its monthly Critical Security Patch Update (CSPU) with patches for 77 vulnerabilities, including a dozen critical-severity flaws.

Announced in early May, the monthly rollouts are meant to supplement the quarterly Critical Patch Update (CPU) fixes and resolve high-priority issues faster.

The first CSPU landed at the end of May and will be followed by another in mid-June. July will see the release of a quarterly CPU, with two additional CSPUs planned for August 18 and September 15.

The May 2026 CSPU resolves security defects in five Oracle products, namely Database Server, REST Data Services, Communications, E-Business Suite, and Hospitality Applications.

E-Business Suite received 12 new security patches, including three for vulnerabilities that can be exploited remotely, without authentication.

Oracle announced 11 new security patches for REST Data Services, including seven for bugs exploitable by remote, unauthenticated attackers. The fixes also resolve four bugs in third-party components, including...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE