# Oracle's Massive June Patch Wave Brings 245 Fixes—But Attackers Are Already Exploiting Older Gaps
## The Threat
Oracle has released its second monthly Critical Security Patch Update (CSPU) of 2026, delivering 245 security fixes across its enterprise software portfolio. The June update signals an aggressive new cadence: Oracle is now supplementing its traditional quarterly Critical Patch Updates with dedicated monthly releases to address the most severe vulnerabilities faster. This represents a significant shift in Oracle's patching strategy, driven by the reality that critical flaws are being weaponized within weeks of disclosure.
The breadth of the June CSPU is striking. Approximately 120 of the 245 vulnerabilities carry critical-severity ratings based on CVSS scoring. More alarmingly, over 100 of these flaws can be exploited remotely without requiring any form of authentication—meaning an attacker with network access can potentially compromise systems without credentials or user interaction. The lion's share of vulnerabilities (over 100 high and critical flaws) are concentrated in Oracle Fusion Middleware, a widely deployed integration platform used by thousands of organizations globally.
What makes this update particularly urgent is Oracle's acknowledgment of active exploitation in the wild. The company stated that it "continues to periodically receive reports of attempts to maliciously exploit vulnerabilities for which Oracle has already released security patches," and warned that "in some instances, it has been reported that attackers have been successful because targeted customers had failed to apply available Oracle patches." This gap between patch release and deployment remains one of the industry's most persistent failure modes—and attackers are actively capitalizing on it.
## Severity and Impact
| Aspect | Details |
|--------|---------|
| CVE Examples | CVE-2026-35273 (PeopleSoft RCE — actively exploited by ShinyHunters), multiple additional CVEs in Fusion Middleware |
| Total Vulnerabilities | 245 |
| Critical Severity | ~120 vulnerabilities (CVSS 9.0–10.0 range typical) |
| Remote Exploitability | 100+ flaws exploitable remotely without authentication |
| Attack Complexity | Low for majority of critical flaws |
| Authentication Required | None for 100+ vulnerabilities |
| Affected Component Concentration | Oracle Fusion Middleware (100+ critical/high severity flaws) |
## Affected Products
Oracle's June 2026 CSPU impacts the following product lines:
Organizations deploying any combination of these products across their enterprise infrastructure should prioritize patching immediately.
## Mitigations
Immediate Actions:
1. Prioritize Critical Vulnerabilities in Fusion Middleware — If your organization uses Oracle Fusion Middleware, WebLogic, or Forms Server, deploy the June 2026 CSPU patches immediately. The concentration of critical flaws in this component makes it the highest-priority target.
2. Apply Patches Without Delay — Given active exploitation of older vulnerabilities (such as CVE-2026-35273), every day without patching increases your breach risk. Oracle's advisory makes clear that attackers are actively scanning for unpatched systems.
3. Network Segmentation — If you cannot patch immediately due to operational constraints, implement strict network segmentation to limit access to vulnerable systems. Restrict remote access to Oracle systems to trusted IP ranges only. Disable unnecessary remote services (RDP, SSH, etc.) on systems running vulnerable Oracle software.
4. Monitoring and Detection — Deploy network intrusion detection signatures (IDS/IPS rules) for known Oracle exploitation attempts. Monitor logs for failed authentication attempts against Oracle databases and middleware components. Enable verbose logging on WebLogic and PeopleSoft instances.
5. Staged Deployment — For organizations with complex environments, deploy patches to non-production systems first to validate compatibility. Use Oracle's patch advisories to identify any known compatibility issues with your specific configurations.
6. Credential Hygiene — Strengthen access controls for Oracle administrative accounts. Implement multi-factor authentication for administrative access to vulnerable systems where feasible.
## References
---
## HackWire Analysis
Oracle's shift to monthly security patch cycles signals a tectonic shift in enterprise vulnerability management. For years, the industry defaulted to quarterly patching windows—a rhythm that afforded organizations planning time but also gave attackers an extended window to weaponize known flaws. This June CSPU, following Oracle's inaugural monthly patch in May, suggests the company has concluded that quarterly windows no longer align with attack velocity.
The education sector targeting by ShinyHunters using CVE-2026-35273 deserves closer scrutiny. Universities and colleges operate on fixed budget cycles and often deprioritize security patching in favor of uptime-first operating models. The attackers clearly identified this as a soft target. The reported 100-organization impact likely represents only the detected intrusions; the actual footprint could be substantially larger. Educational institutions now face an uncomfortable calculus: do they patch during summer semester (disrupting research systems and administrative operations) or wait until fall (gambling that attackers won't return)?
The most damning finding in Oracle's advisory is the admission that organizations are being breached because they failed to apply *already released* patches. This isn't a zero-day problem; this is a patching execution problem. It suggests that many enterprises have broken or overwhelmed patch management processes. Fusion Middleware is notoriously difficult to patch due to its interconnected dependencies—but the concentration of 100+ critical flaws in one component creates a pressure cooker. The risk of leaving systems unpatched is now objectively worse than the risk of patching-induced downtime.
Organizations using Oracle should treat the June 2026 CSPU as a crisis-mode deployment, not a routine maintenance window. The window between patch release and active exploitation continues to narrow—and this month, the attackers are already inside.
— HackWire Editorial
---
## Related Coverage