This Critical Patch Update Pre-Release Announcement provides advance information about the Oracle Critical Patch Update for April 2026, which will be released on Tuesday, April 21, 2026. While this Pre-Release Announcement is as accurate as possible at the time of publication, the information it contains may change before publication of the Critical Patch Update Advisory.
A Critical Patch Update is a collection of patches for multiple security vulnerabilities. This Critical Patch Update addresses 483 new security patches. Some of the vulnerabilities addressed in this Critical Patch Update affect multiple products. Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Critical Patch Update patches as soon as possible.
This Critical Patch Update contains 8 new security patches for Oracle Database Products. 4 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. None of these patches are applicable to client-only installations, i.e., installations that do not have the Oracle Database Server installed.
The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Database Server is 7.5.
The Oracle Database Server components and versions affected by vulnerabilities that are addressed in this Critical Patch Update are:
This Critical Patch Update contains 2 new security patches for Oracle Adapter for Eclipse RDF4J. Both of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.
The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Adapter for Eclipse RDF4J is 7.5.
The Oracle Adapter for Eclipse RDF4J products and versions affected by vulnerabilities that are addressed in this Critical Patch Update are:
This Critical Patch Update contains 1 new security patch for Oracle Autonomous Health Framework. This vulnerability is remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.
The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Autonomous Health Framework is 5.9.
The Oracle Autonomous Health Framework products and versions affected by vulnerabilities that are addressed in this Critical Patch Update are:
This Critical Patch Update contains 6 new security patches for Oracle Blockchain Platform. 4 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.
The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Blockchain Platform is 7.5.
The Oracle Blockchain Platform products and versions affected by vulnerabilities that are addressed in this Critical Patch Update are:
This Critical Patch Update contains 10 new security patches for Oracle GoldenGate. 7 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.
The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle GoldenGate is 7.5.
The Oracle GoldenGate products and versions affected by vulnerabilities that are addressed in this Critical Patch Update are:
This Critical Patch Update contains 1 new security patch for Oracle NoSQL Database. This vulnerability is remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.
The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle NoSQL Database is 5.3.
The Oracle NoSQL Database products and versions affected by vulnerabilities that are addressed in this Critical Patch Update are:
This Critical Patch Update contains 2 new security patches for Oracle REST Data Services. Both of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.
The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle REST Data Services is 7.5.
The Oracle REST Data Services products and versions affected by vulnerabilities that are addressed in this Critical Patch Update are:
This Critical Patch Update contains 1 new security patch for Oracle TimesTen In-Memory Database. This vulnerability is remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.
The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle TimesTen In-Memory Database is 7.4.
The Oracle TimesTen In-Memory Database products and versions affected by vulnerabilities that are addressed in this Critical Patch Update are:
This Critical Patch Update contains 3 new security patches for Oracle Commerce. 2 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.
The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Commerce is 8.8.
The Oracle Commerce products and versions affected by vulnerabilities that are addressed in this Critical Patch Update are:
This Critical Patch Update contains 137 new security patches for Oracle Communications. 91 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.
The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Communications is 9.8.
The Oracle Communications products and versions affected by vulnerabilities that are addressed in this Critical Patch Update are:
This Critical Patch Update contains 4 new security patches for Oracle Construction and Engineering. 3 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.
The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Construction and Engineering is 6.5.
The Oracle Construction and Engineering products and versions affected by vulnerabilities that are addressed in this Critical Patch Update are:
This Critical Patch Update contains 18 new security patches for Oracle E-Business Suite. 8 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.
The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle E-Business Suite is 9.8.
The Oracle E-Business Suite products and versions affected by vulnerabilities that are addressed in this Critical Patch Update are:
This Critical Patch Update contains 10 new security patches for Oracle Enterprise Manager. 9 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. None of these patches are applicable to client-only installations, i.e., installations that do not have Oracle Enterprise Manager installed.
The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Enterprise Manager is 9.1.
The Oracle Enterprise Manager products and versions affected by vulnerabilities that are addressed in this Critical Patch Update are:
This Critical Patch Update contains 73 new security patches for Oracle Financial Services Applications. 57 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.
The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Financial Services Applications is 9.8.
The Oracle Financial Services Applications products and versions affected by vulnerabilities that are addressed in this Critical Patch Update are:
This Critical Patch Update contains 59 new security patches for Oracle Fusion Middleware. 46 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.
The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Fusion Middleware is 9.8.
The Oracle Fusion Middleware products and versions affected by vulnerabilities that are addressed in this Critical Patch Update are:
This Critical Patch Update contains 16 new security patches for Oracle Analytics. 12 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.
The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Analytics is 9.8.
The Oracle Analytics products and versions affected by vulnerabilities that are addressed in this Critical Patch Update are:
This Critical Patch Update contains 2 new security patches for Oracle Life Science Applications. Both of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.
The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Life Science Applications is 6.5.
The Oracle Life Science Applications products and versions affected by vulnerabilities that are addressed in this Critical Patch Update are:
This Critical Patch Update contains 1 new security patch for Oracle Hospitality Applications. This vulnerability is remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.
The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Hospitality Applications is 7.5.
The Oracle Hospitality Applications products and versions affected by vulnerabilities that are addressed in this Critical Patch Update are:
This Critical Patch Update contains 6 new security patches for Oracle Hyperion. 4 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.
The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Hyperion is 7.5.
The Oracle Hyperion products and versions affected by vulnerabilities that are addressed in this Critical Patch Update are:
This Critical Patch Update contains 12 new security patches for Oracle Java SE. 8 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.
The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Java SE is 7.5.
The Oracle Java SE products and versions affected by vulnerabilities that are addressed in this Critical Patch Update are:
This Critical Patch Update contains 3 new security patches for Oracle JD Edwards. All of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.
The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle JD Edwards is 7.5.
The Oracle JD Edwards products and versions affected by vulnerabilities that are addressed in this Critical Patch Update are:
This Critical Patch Update contains 34 new security patches for Oracle MySQL. 3 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.
The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle MySQL is 9.8.
The Oracle MySQL products and versions affected by vulnerabilities that are addressed in this Critical Patch Update are:
This Critical Patch Update contains 21 new security patches for Oracle PeopleSoft. 7 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.
The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle PeopleSoft is 8.8.
The Oracle PeopleSoft products and versions affected by vulnerabilities that are addressed in this Critical Patch Update are:
This Critical Patch Update contains 17 new security patches for Oracle Retail Applications. 15 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.
The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Retail Applications is 7.5.
The Oracle Retail Applications products and versions affected by vulnerabilities that are addressed in this Critical Patch Update are:
This Critical Patch Update contains 14 new security patches for Oracle Siebel CRM. 13 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.
The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Siebel CRM is 7.7.
The Oracle Siebel CRM products and versions affected by vulnerabilities that are addressed in this Critical Patch Update are:
This Critical Patch Update contains 4 new security patches for Oracle Supply Chain. 2 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.
The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Supply Chain is 8.8.
The Oracle Supply Chain products and versions affected by vulnerabilities that are addressed in this Critical Patch Update are:
This Critical Patch Update contains 2 new security patches for Oracle Systems. 1 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.
The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Systems is 9.0.
The Oracle Systems products and versions affected by vulnerabilities that are addressed in this Critical Patch Update are:
This Critical Patch Update contains 7 new security patches for Oracle Utilities Applications. 6 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.
The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Utilities Applications is 7.5.
The Oracle Utilities Applications products and versions affected by vulnerabilities that are addressed in this Critical Patch Update are:
This Critical Patch Update contains 9 new security patches for Oracle Virtualization. 1 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.
The highest CVSS v3.1 Base Score of vulnerabilities affecting Oracle Virtualization is 7.5.
The Oracle Virtualization products and versions affected by vulnerabilities that are addressed in this Critical Patch Update are: