Oracle has released the new Critical Security Patch Update (Oracle CSPU) for June 2026 , continuing the strategy it launched this year with the release of monthly security patches . This is the second monthly update that the company has released, complementing the traditional quarterly Critical Patch Update schedule that it has been following for years.

Oracle's decision to increase the frequency of patches reflects the increasing pressure on businesses from cyberattacks. As attackers exploit new vulnerabilities more quickly, software makers are being challenged to reduce the time between discovering a problem and releasing a fix.
245 security fixes in critical Oracle
The June update includes a total of 245 new security fixes across a wide range of Oracle products. These include popular enterprise platforms such as Oracle Fusion Middleware, Oracle E-Business Suite, Enterprise Manager, MySQL, PeopleSoft, JD Edwards, Siebel CRM, as well as solutions related to infrastructure, virtualization, and systems management.
See also: Oracle releases 337 security patches
The scope of the fixes reveals just how extensive Oracle’s ecosystem is, used by thousands of organizations worldwide in mission-critical operations. Any security weakness in such platforms could be a potential entry point for cybercriminals, with serious consequences for data, services and corporate infrastructure.
Over 100 critical vulnerabilities cause concern
Of particular interest is the fact that almost half of the vulnerabilities addressed are classified as critical according to the international CVSS scoring system.

Specifically, approximately 120 security vulnerabilities are rated “Critical”, while nearly 100 of them can be exploited remotely without requiring any form of authentication from the attacker. This is one of the most dangerous categories of vulnerabilities, as they allow attacks to be carried out without physical access to the system or valid user credentials.
In an environment where ransomware attacks and corporate network breaches are at historic highs, such vulnerabilities are a prime target for cybercriminal groups.
Fusion Middleware: Oracle's big "headache"
Of the total fixes, more than 100 concern Oracle Fusion Middleware, one of the company's most important platforms for enterprise applications and cloud services.
The fact that the majority of these vulnerabilities have been rated as high or critical severity shows how attractive these infrastructures remain for attackers. Middleware platforms often act as the connecting link between different enterprise applications and databases, making them particularly valuable in the event of a breach.
Cybersecurity experts point out that organizations using such solutions should implement updates as soon as possible, as delay creates opportunities for malicious actions.
See also: ShinyHunters: Massive attacks against Oracle PeopleSoft for data theft
Oracle warns of delays in installing updates
In its announcement, Oracle emphasized once again that several successful attacks recorded in recent years were not due to a lack of available fixes, but to the inability or delay of organizations to install them.
The company says it continues to receive reports of attacks exploiting known vulnerabilities that had already been patched in previous security updates. This problem is one of the biggest challenges in cybersecurity, as many businesses delay upgrades for fear of disrupting critical systems.

PeopleSoft and the ShinyHunters attack reports
Although Oracle has not publicly confirmed the existence of active zero-day attacks, recent reports from security firms link the cybercriminal ShinyHunters to the exploitation of the CVE-2026-35273 vulnerability in Oracle PeopleSoft.
According to the relevant information, more than 100 organizations have reportedly been targeted by the attacks, with a significant number of victims coming from the education. Although this vulnerability is included in recent Oracle updates, the company has not officially reported any incidents of its active exploitation.
See also: CISA warns of Oracle WebLogic vulnerability exploitation
The speed of updates becomes a critical factor
The new June CSPU confirms that Oracle is adapting to the modern demands of the threat landscape by adopting a more aggressive pace of security patch releases. For enterprises relying on the company’s platforms, timely installation of updates is no longer just a best practice, but a prerequisite for protecting critical data and business infrastructure against increasingly sophisticated cyber threats.
