Oracle fixes 245 vulnerabilities in its June update

Oracle has released its June 2026 security patches, covering 245 vulnerabilities across product families including Oracle Communications, E-Business Suite, Enterprise Manager, Fusion Middleware, JD Edwards, MySQL, PeopleSoft, Siebel CRM, Supply Chain, Systems and Virtualization. The bulk sits in Fusion Middleware with 106 patches, 53 of them for vulnerabilities remotely exploitable without authentication. Several carry a CVSS score of 10.0 and affect products such as Coherence, WebCenter Enterprise Capture, WebCenter Portal, WebCenter Sites and WebLogic Server. The update also includes the fix for PeopleSoft PeopleTools CVE-2026-35273, issued as a separate alert on 10 June.

What this means for your organisation

Oracle products typically sit at the centre of finance, HR and logistics processes, and they are rarely taken offline at short notice. That is precisely why they stay unpatched. An internet-facing WebLogic server exploitable without credentials is among the most attractive entry points an attacker can find. The combination of critical ERP data and a slow patch cycle makes this a board matter, not just an operations task.

Berigo recommends

  • Map which Oracle components you actually expose to the internet, and patch those first.
  • Prioritise Fusion Middleware, particularly WebLogic and WebCenter, ahead of the rest of the estate.
  • Clarify with your supplier who is responsible for installing these updates under your operations and hosting agreements.
  • Set a completion deadline through change management rather than waiting for the next routine maintenance window.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch