Malware

Oracle Patches 35 Vulnerabilities in First Monthly Security Update

via RSS: CSO Online
Oracle Patches 35 Vulnerabilities in First Monthly Security Update

Oracle has launched its new monthly Critical Security Patch Update (CSPU) program to address urgent security flaws that cannot wait for quarterly patches. The first batch fixes 35 vulnerabilities: 11 critical, 18 high, and 6 medium severity. Critical flaws affect Oracle REST Data Services, E-Business Suite, Universal Work Queue, and Payments modules. Notably, CVE-2026-46840 has a perfect CVSS score of 10, affecting REST Data Services' backend-as-a-service component, allowing unauthenticated attackers to compromise the database gateway via HTTPS. Several vulnerabilities have publicly available exploit code, including flaws in Oracle Communications Unified Assurance. Indian organizations using Oracle products should prioritize patching these critical issues promptly. Source: The Register.

Read the full story

Original reporting by RSS: CSO Online. We only summarise โ€” never republish.

Open source