Vulnerabilities · 132 days ago
Oracle is shifting critical Oracle patching from a quarterly rhythm to a monthly one for self-managed environments, so the old CPU schedule no longer keeps exposure windows aligned across Oracle customers. Oracle-managed services still update automatically, so the operational burden now falls more heavily on database, ERP, and OCI teams that run their own deployments.
Oracle’s first monthly Critical Security Patch Update is due May 28, with follow-on releases on June 16 and August 18. The usual quarterly CPU still continues in July and will include both new fixes and the earlier monthly patches, which confirms the change is about delivery speed and patch cadence, not a specific active exploit.
For security teams, the practical shift is that critical Oracle fixes can arrive between quarterly maintenance windows. That leaves self-managed estates exposed longer if they keep planning around the old CPU cycle.
3 sources covering this story
Oracle Debuts Monthly Critical Security Patch Updates
Containing fixes for critical-severity vulnerabilities, the monthly rollouts will focus on addressing priority issues faster.
Oracle rolls out monthly security patch updates - Help Net Security
Oracle is using AI to improve vulnerability detection and response across environments, and is rolling out monthly security updates.
Oracle will patch more often to counter AI cybersecurity threat
Oracle will follow SAP, Microsoft and other software vendors in issuing security patches monthly — but a week later than everyone else.
Part of the PlainSec briefing for 2026-05-07