Oracle is shifting critical Oracle patching from a quarterly rhythm to a monthly one for self-managed environments, so the old CPU schedule no longer keeps exposure windows aligned across Oracle customers. Oracle-managed services still update automatically, so the operational burden now falls more heavily on database, ERP, and OCI teams that run their own deployments.
Oracle’s first monthly Critical Security Patch Update is due May 28, with follow-on releases on June 16 and August 18. The usual quarterly CPU still continues in July and will include both new fixes and the earlier monthly patches, which confirms the change is about delivery speed and patch cadence, not a specific active exploit.
For security teams, the practical shift is that critical Oracle fixes can arrive between quarterly maintenance windows. That leaves self-managed estates exposed longer if they keep planning around the old CPU cycle.