Oracle ships 943 security fixes, one rated a perfect 10

Oracle has released 943 security patches in an August Critical Security Patch Update, and the worst single item in it carries the maximum score the scale allows. CVE-2026-61241, in the LDAP server component of Oracle Internet Directory, is rated CVSS 10.0: reachable over the network, low attack complexity, no privileges required, no user interaction, and scored as reaching beyond the component it lands in. Versions 12.2.1.4.0 and 14.1.2.1.0 are listed as affected.

The release is not the quarterly cycle most Oracle shops plan their maintenance around. Oracle describes a Critical Security Patch Update as targeted, high priority security fixes in a smaller, more focused format that is easier to apply with minimal disruption, complementing the cumulative quarterly Critical Patch Updates rather than replacing them. Hong Kong's CERT relayed the batch to its constituents on 19 August in a short bulletin; the substance is in Oracle's own advisory, and that is the document to work from.

Where the 943 actually land

Two product families take more than half the release. Oracle Fusion Middleware accounts for 262 patches, of which Oracle says 182 may be remotely exploitable without authentication, meaning over a network with no credentials at all. Oracle Hyperion also takes 262, with 107 in that category. After those: E-Business Suite 120 patches (27 remotely exploitable without authentication), Oracle Commerce 66 (47), Siebel CRM 50 (21), Supply Chain products 46, Virtualization 21 (2), PeopleSoft 15, Communications 13, Enterprise Manager 11, MySQL 9 (5), Database Server 6 (4) and Java SE 5 (4).

Inside Fusion Middleware, behind the Internet Directory flaw, sit CVE-2026-73930 in Helidon's imperative web server at 9.9, and CVE-2026-60720 in Oracle Identity Manager's legacy interface, also 9.9 but not flagged as remotely exploitable without authentication. The affected version ranges are wide. Oracle Database Server covers 19.3 to 19.32, 21.3 to 21.23 and 23.4.0 to 23.26.3; E-Business Suite covers 12.2.3 to 12.2.15; Oracle Access Manager, like Internet Directory, covers 12.2.1.4.0 and 14.1.2.1.0.

Directory servers first, then anything internet-facing

Oracle does not publish exploitation detail, and nothing here is described as being under attack, so the order of work has to come from exposure rather than from threat reporting. An unauthenticated, network-reachable flaw in the directory that other systems trust to answer the question of who a user is belongs at the front of the queue. Middleware and commerce tiers follow, since that is where the unauthenticated counts are concentrated. Patch availability documents are linked per product family from the advisory, and administrators of the smaller families should not read a low patch count as a low risk: Java SE has five patches and four of them are remotely exploitable without authentication.

Oracle attaches a standard warning to releases like this one, and it reads better as a finding than as boilerplate. The company says it continues to receive reports of attempts to exploit vulnerabilities for which patches have already been released, and that in some instances attackers succeeded because the targeted customers had failed to apply them. That is the pattern this site keeps recording. Oracle software turned up on CISA's exploited list in July, and a PeopleSoft flaw was used against universities in June. The window that gets exploited is rarely the one between disclosure and patch. It is the one between patch and deployment.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions