Skip to content
Wednesday, August 26, 2026
KAJ NEWSCYBER · PRIVACY · SECURITY
Home / Cybersecurity News
Cybersecurity News

Oracle's January 2026 patch batch fixes 158 CVEs, with dozens remotely exploitable without credentials

Oracle's first Critical Patch Update of 2026 shipped 337 security fixes across its product family on January 20, and analysis shows 27 issues remotely exploitable without authentication.

Malik Johnson, · February 6, 2026 · 2 min read
ShareXFacebookLinkedInTelegramEmail
Bar chart of Oracle quarterly security fix counts trending upward

Oracle released its January 2026 Critical Patch Update on January 20, 2026, delivering 337 new security fixes for vulnerabilities across Oracle's database, middleware, applications, and virtualization products. Analysis by security firm Tenable counted 158 unique CVEs in the release and flagged 27 issues — roughly 8% of the patches — as remotely exploitable without authentication, the profile that matters most to anyone running internet-facing Oracle systems. No active exploitation of the January flaws was confirmed in the materials published by early February.

What is a Critical Patch Update?

Oracle's CPUs arrive quarterly — January, April, July, October — and bundle fixes across the company's entire portfolio in one coordinated release, per Oracle's advisory. Each advisory lists affected components, severity guidance, and the minimum patch versions. The January 2026 release followed the standard cadence; its scope, 337 fixes covering 158 CVEs per Tenable's analysis, sits within the typical range of recent CPUs, which have been running between roughly 300 and 400 fixes per quarter.

Which systems matter most?

Priorities differ sharply by exposure. Internet-facing Oracle HTTP Server, WebLogic, and E-Business Suite deployments warrant immediate attention — remotely exploitable-without-authentication flaws in exposed middleware are the classic Oracle breach path, as past CPU cycles have repeatedly demonstrated. Database and Fusion Middleware installations on internal networks follow, then the long tail of application-layer fixes. The highest-risk scoring in the advisory clustered in components that organizations commonly expose to partners and remote users, a pattern consistent with previous quarters.

What should you do now?

  1. Inventory first. List which Oracle products and versions your organization actually runs — the CPU applies per-component, and patching starts with knowing what you host.
  2. Patch exposed systems this week. Apply the January CPU to anything internet-facing, prioritizing components Tenable flagged as remotely exploitable without authentication.
  3. Schedule the rest within the month. Internal systems can follow a normal change window, but the next CPU lands in April — falling behind one cycle means carrying unpatched flaws into the next quarter.
  4. Check CISA's KEV catalog for any Oracle CVEs added after this release; a KEV listing means attackers are using the flaw and the patch deadline is now.

For an ecosystem where a single missed quarter has repeatedly led to mass exploitation, the quarterly rhythm is the entire defense: January's batch is installed, April's is scheduled, and nothing Oracle-shaped faces the internet unpatched.

Frequently Asked Questions

How many vulnerabilities did Oracle fix in January 2026?
The January 20, 2026 Critical Patch Update delivered 337 security fixes covering 158 unique CVEs, per Oracle's advisory and Tenable's analysis. Twenty-seven issues were rated remotely exploitable without authentication.
When is the next Oracle CPU?
Oracle ships Critical Patch Updates quarterly in January, April, July, and October. The next release after January 2026 is the April 2026 CPU.
Do I need to patch if my Oracle systems are internal-only?
Yes, but on a slower clock. Remotely exploitable flaws in exposed middleware demand immediate patching; internal systems should be updated within the month, since lateral movement after an initial breach makes internal unpatched systems the second wave of victims.