Oracle said it will replace its quarterly security patching model with monthly Critical Security Patch Updates for ERP, database, and other software products, citing the faster pace of AI-enabled vulnerability discovery. The company said the new cadence is intended to shorten exposure windows as attackers and researchers use AI to identify software flaws more quickly.
The first monthly release is scheduled for May 28, after which Oracle plans to move to a regular third-Tuesday schedule each month. Reported upcoming dates include June 16, July 21, and August 18. The move brings Oracle closer to the monthly patching approach already used by major software vendors including Microsoft, SAP, and Adobe, though those vendors typically release updates on the second Tuesday of the month.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Oracle released a security advisory detailing patches for multiple enterprise products, including severe remotely exploitable vulnerabilities such as CVE-2026-46833 in Oracle Net Service and CVE-2026-46840 in Oracle REST Data Services Backend-as-a-Service. The advisory also warned of ongoing exploitation attempts against already-patched Oracle flaws and urged immediate patching of exposed systems.
Oracle said its first monthly Critical Security Patch Update will be released on May 28 as an initial fourth-Thursday release. After that, the company plans to adopt a regular patch cadence on the third Tuesday of each month.
Oracle said it will move its ERP, database, and other software products from a quarterly security patch cadence to monthly Critical Security Patch Updates. The company cited the faster pace of AI-enabled vulnerability discovery as the reason for the change.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
cio.com
Open sourcecybersecuritynews.com
Open sourcesecurityonline.info
Open sourceoracle.com
Open sourcecio.com
Open sourceinfoworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.