DSP Blog

Oracle Critical Patch Update January 2026

Written by Ben Morris | 21-Jan-2026 11:03:32

Each quarter, Oracle issues a Critical Patch Update (CPU), a consolidated release of security fixes that addresses a broad spectrum of vulnerabilities across its product stack. These updates are specifically engineered to reduce exposure to emerging threats, from code-level weaknesses to flaws in embedded third-party components. Regularly implementing these CPUs is one of the most effective ways to strengthen the security posture and operational resilience of your Oracle estate.

This quarter’s Critical Patch Update includes 337 new security fixes across the Oracle portfolio, resolving 238 critical vulnerabilities that in many cases can be exploited remotely without authentication. To safeguard your Oracle estate and minimise exposure, these CPU patches should be scheduled and applied with the highest priority.

 

What should I do?

Below is a list of affected products and the number of identified vulnerabilities for each. If you use any of these products, you must take the necessary action to address the potential vulnerabilities in your estate. But don’t worry. DSP is here to help. Customers frequently approach us at this time to utilise our Oracle Critical Patch Update Support Service to help stay on top of their patches. So, please get in touch if this is an area of concern for you.

 

List of identified products and vulnerabilities

The number in bold = the number of security patches

The numbers in (brackets) = the number of vulnerabilities

Although a long list of vulnerabilities might seem daunting, securing your hardware and applications is essential. You can protect your environment effectively by staying proactive and regularly applying Critical Patch Updates. Here is the list for details on all the patches. Your system's safety is our priority.

If you would like Oracle Critical Patch Update Support, please Contact Us or book a meeting...