Oracle August 2026 CSPU: 943 patches, including WebLogic 9.8 and OID 10.0
Oracle's 18 August 2026 Critical Security Patch Update (revision 3 on 27 August) contains 943 new security patches. Oracle says it continues to receive reports of attempts to exploit already-patched issues where customers had not applied available updates. Fusion Middleware includes unauthenticated WebLogic Server Core issues CVE-2026-60698 (IIOP, 9.8), CVE-2026-60672 and CVE-2026-60696 (T3/IIOP, 9.8) on 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0, plus CVE-2026-60977 (RMI, 9.8) on 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0, and Oracle Internet Directory LDAP Server CVE-2026-61241 at 10.0 on 12.2.1.4.0 and 14.1.2.1.0. Database Server includes adjacent-network Portable Clusterware issues CVE-2026-71063 and CVE-2026-71064 at 9.6. Apply the August 2026 CSPU for each product family you run. This is separate from CVE-2026-21962 (January 2026 CPU, later added to CISA KEV).
- Product
- Oracle Fusion Middleware, Database Server and other families in the August 2026 CSPU
- Versions
- See the August 2026 CSPU risk matrices; WebLogic 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 among others
- CVSS
- Up to (CVE-2026-61241, CVSS 3.1, Oracle)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- August 2026 Critical Security Patch Update for each affected product
Primary: Oracle CSPU August 2026 · Vendor: Oracle (vendor) · CVE: CVE-2026-60698, CVE-2026-60672, CVE-2026-60696, CVE-2026-60977, CVE-2026-61241, CVE-2026-71063, CVE-2026-71064, CVE-2026-21962
