What's in the Oracle's Critical Patch Update (CPU)?

Now it’s time for Administrators who work with Java applications and Oracle databases to realize what’s in store for them in the new security update from Oracle. More than a third of the security fixes affect Java, MySQL, and Oracle Database Server. Several of these vulnerabilities are considered critical and could be remotely exploited without requiring authentication, Oracle said.
Oracle doesn't state in the Critical Patch Update (CPU) whether any of the vulnerabilities is currently being exploited in the wild. However, it warns that attackers continue to target security holes for which fixes are already available. "In some instances, it has been reported that attackers have been successful because targeted customers had failed to apply available Oracle patches. Oracle therefore strongly recommends that customers remain on actively supported versions and apply Critical Patch Update fixes without delay," the company said in an advisory.
Losing interest in database fixes
The size of this CPU -- 136 fixes -- is actually the second smallest over the past year. Last April's CPU fixed a mere 98 flaws, but subsequent updates have been progressively larger, peaking at 248 patches in January's gargantuan CPU. More than the size of the CPU itself, what's striking is the small number of patches for Oracle Database. Past CPUs have hovered around 10 Oracle Database Server patches, but this month there are only five. Maybe it has something to do with April -- Oracle patched a mere four flaws last April.
MySQL still gets attention
Oracle's lack of attention on databases may be confined to its flagship database since the CPU did not neglect MySQL. Of the 31 new security fixes for Oracle MySQL, four could be exploited remotely without authentication. Both critical vulnerabilities in MySQL Server's packaging subcomponent (CVE-2016-0705) and the critical vulnerability in MySQL Server's pluggable authentication subcomponent (CVE-2016-0639) affect versions 5.6.29 and earlier as well as 5.7.11 and earlier. Oracle assigned a CVSS 3.0 rating of 9.8 (CVSS 2.0 rating of 10.0) and warned that the attack complexity for this flaw was low, meaning attackers don't have to meet any special requirements to access the bug. A successful attack would result in total information disclosure and complete control over the targeted system.
Patch Java or dump it
Oracle patched nine security flaws in Oracle Java SE, which affects Java applets and Java Web Start applications. All of the vulnerabilities can be remotely exploited without a username or password, but the severity depends on the level of privileges assigned to the user. If the user has administrator privileges -- unfortunately still common on Windows systems -- the severity is much higher than if the user has restricted access, a scenario more common for Linux and Solaris users.
Take the next step towards your professional goals in Database Marketing
Don't hesitate to talk with our course advisor right now
Receive a call
Contact NowMake a call
+1-732-338-7323Latest blogs on technology to explore

Drug Safety & Pharmacovigilance: Your 2026 Career Passport to a Booming Healthcare Industry!
Why This Course Is the Hottest Ticket for Science Grads & Healthcare Pros (No Lab Coat Required!)" The Exploding Demand for Drug Safety Experts "Did you know? The global pharmacovigilance market is set to hit $12.5B by 2026 (Grand View Research, 202

Launch Your Tech Career: Why Mastering AWS Foundation is Your Golden Ticket in 2026
There’s one skill that can open all those doors — Amazon Web Services (AWS) Foundation

Data Science in 2026: The Hottest Skill of the Decade (And How Sulekha IT Services Helps You Master It!)
Data Science: The Career that’s everywhere—and Nowhere Near Slowing Down "From Netflix recommendations to self-driving cars, data science is the secret sauce behind the tech you use every day. And here’s the kicker: The U.S. alone will have 11.5 mill

Salesforce Admin in 2026: The Career Goldmine You Didn’t Know You Needed (And How to Break In!)
The Salesforce Boom: Why Admins Are in Crazy Demand "Did you know? Salesforce is the 1 CRM platform worldwide, used by 150,000+ companies—including giants like Amazon, Coca-Cola, and Spotify (Salesforce, 2025). And here’s the kicker: Every single one

Python Power: Why 2026 Belongs to Coders Who Think in Python
If the past decade was about learning to code, the next one is about coding smarter. And in 2026, the smartest move for any IT enthusiast is learning Python — the language that powers AI models, automates the web, and drives data decisions across ind

The Tableau Revolution of 2025
"In a world drowning in data, companies aren’t just looking for analysts—they’re hunting for storytellers who can turn numbers into decisions. Enter Tableau, the #1 data visualization tool used by 86% of Fortune 500 companies (Tableau, 2024). Whether

From Student to AI Pro: What Does Prompt Engineering Entail and How Do You Start?
Explore the growing field of prompt engineering, a vital skill for AI enthusiasts. Learn how to craft optimized prompts for tools like ChatGPT and Gemini, and discover the career opportunities and skills needed to succeed in this fast-evolving indust

How Security Classification Guides Strengthen Data Protection in Modern Cybersecurity
A Security Classification Guide (SCG) defines data protection standards, ensuring sensitive information is handled securely across all levels. By outlining confidentiality, access controls, and declassification procedures, SCGs strengthen cybersecuri

Artificial Intelligence – A Growing Field of Study for Modern Learners
Artificial Intelligence is becoming a top study choice due to high job demand and future scope. This blog explains key subjects, career opportunities, and a simple AI study roadmap to help beginners start learning and build a strong career in the AI

Java in 2026: Why This ‘Old’ Language Is Still Your Golden Ticket to a Tech Career (And Where to Learn It!
Think Java is old news? Think again! 90% of Fortune 500 companies (yes, including Google, Amazon, and Netflix) run on Java (Oracle, 2025). From Android apps to banking systems, Java is the backbone of tech—and Sulekha IT Services is your fast track t