Cyber Resilience
← All news
Confirmed3

Oracle security advisory – July 2026 quarterly rollup (AV26-729)

Oracle's July 2026 rollup addresses issues in Database Server, APEX, GoldenGate and several other products. Enterprises running these on-prem should review the advisory; most smaller teams can skip unless they self-host any of them.
Sources (1)
What this means for you — CISO:Review AV26-729 against your Oracle estate—Database Server, APEX, Autonomous Health Framework, Essbase, GoldenGate, NoSQL, and related components—and schedule the critical updates on your normal quarterly change window unless a specific CVE is already under active exploit in your environment.
What this means for you — Lean IT orgs:Most lean-IT shops do not run Oracle Database or the other products in this rollup and can ignore it; if a payroll, ERP, or other vendor you depend on uses Oracle, ask them whether they have applied the July 2026 patches.
What this means for you — MSP:Inventory clients for Oracle Database Server, APEX, GoldenGate, Essbase, NoSQL, and the other products named in AV26-729; queue critical updates only for estates that actually run them and note the rest as not applicable.
What this means for you — Researcher:Pull the July 2026 Critical Patch Update diff for the listed Oracle products and compare severity, remote-exploitability, and any already-weaponized CVEs against prior quarterly rollups.