Oracle Communications Takes the Biggest Hit in April CPU

Oracle’s April CPU is not a routine patch cycle for teams running Oracle Communications. The problem is the concentration of remotely exploitable, unauthenticated flaws, which means exposed systems can be attacked before any login barrier gets in the way. Oracle released 481 new security patches across 28 product families, with more than 300 fixes for remotely exploitable, unauthenticated vulnerabilities and roughly 450 unique CVEs on the update page. Oracle Communications received 139 patches, including 93 for unauthenticated remote issues; Financial Services Applications and Fusion Middleware were the next largest buckets. For defenders, the immediate risk is not the patch count itself. It is the number of Oracle products that now carry internet-reachable attack surface, with Oracle Communications standing out as the most concentrated exposure area in this cycle.

Part of the PlainSec briefing for 2026-04-23

Sources