← Intelligence Center

Oracle Quarterly Critical Patches Issued July 21, 2026

PublishedJul 22, 2026
Updated
VendorOracle
SeverityHigh
Known ExploitedNo
Advisory IDINTEL-000005
CVEs
None identified.
Products
  • GoldenGate Stream Analytics 19.1.0.0.0-19.1.0.0.15, 26.1.0.0.0
  • JD Edwards EnterpriseOne Advanced Pricing - Procurement, Configurator, CRM Foundation, General Ledger, HCM Foundation, Human Resources Management, Procurement and Subcontract Management, Requirements Planning, Solution Advisor (9.2); Tools 9.2.26.3
  • Management Cloud Engine 25.2.0.0.0
  • MySQL Cluster, MySQL Connectors, MySQL Router, MySQL Server
  • OPatch 12.2.0.1.16-12.2.0.1.51
  • Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0, 15.1.1.0.0
  • Oracle Agile Engineering Data Management 6.2.1, Agile PLM 9.3.6, Agile PLM MCAD Connector
  • Additional Oracle product families covered by the July 21, 2026 Critical Patch Update (full list in the referenced Oracle announcement)

Executive Summary

MS-ISAC Advisory 2026-071 (issued 7/22/2026): Oracle issued its quarterly Critical Patch Update on July 21, 2026, covering a wide range of Oracle products. The most severe vulnerabilities could allow for remote code execution in the context of the logged-on user. A full list of all vulnerabilities is contained in the Oracle announcement referenced in the advisory. There are currently no reports of these vulnerabilities being exploited in the wild.

Municipal Impact

MS-ISAC rates the risk as High for large, medium, and small government entities; municipal organizations running Oracle products should plan to apply the July 2026 Critical Patch Update.

SMB Impact

MS-ISAC rates the risk as High for large, medium, and small business entities and Low for home users.

Recommended Actions

  1. Apply appropriate updates provided by Oracle to vulnerable systems immediately after appropriate testing.
  2. Review the full Oracle Critical Patch Update announcement for a complete list of affected products and patches.
  3. Follow CIS Safeguards for vulnerability management, automated vulnerability scanning, and remediation.

Grey Matter Analysis

Analysis pending review.

Need help with this advisory?

Contact Grey Matter to assess your exposure and prioritize remediation.

Contact Grey Matter