Oracle fixes 481 vulnerabilities in its April quarterly update

Oracle has released its Critical Patch Update advisory for April 2026, addressing 481 vulnerabilities across a wide range of products with CVSS ratings from 2.3 to 9.8. The vendor notes that patches are usually cumulative, but that each advisory describes only the security patches added since the previous one. Earlier advisories should therefore be reviewed.

What this means for your organisation

The volume means nobody gets through all of it, so prioritisation is the real task. For most Norwegian organisations the difficulty is not installing the patches but knowing which Oracle products are actually running. Databases, middleware and application servers often arrive bundled inside a larger delivery, and responsibility for updating them is not always settled between customer and supplier.

Berigo recommends

  • Obtain a current inventory of which Oracle products and versions you run, including those bundled with other deliveries.
  • Prioritise systems that are internet-facing or process personal data, rather than going by CVSS scores alone.
  • Settle in writing who is responsible for Oracle patching in your contracts with operations providers.
  • Check for backlog from earlier quarterly updates, since the advisory describes only what is new.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch