Oracle May 2026 Critical Security Patch Update Addresses 35 CVEs
2026-05-29T08:52:21Z•104f00d1f85d8ed9228fc972a8a539ea02b9f8bd5ab68d135f94716c39ebc95c
35 CVEsCI/CD compromiseCVE-2026-9082DrupalEXPOSURE 2026Mini Shai-HuludOracle CSPU May 2026PostgreSQLPyPISLSA Build Level 3SQL injectionTeamPCPTenable One Open Connectorcredential theftcritical patchesexposure managementnpmnpm download pumpingpackage ecosystemprovenance bypassself-propagating wormsupply chain attack
What happened
Tenable published multiple security updates and research briefings in May 2026: Oracle's May 2026 Critical Security Patch Update (CSPU) fixes 35 CVEs across five product families, including 11 critical issues; Tenable researchers disclosed a new npm deception technique (“download pumping”) that inflates download metrics to hide malicious packages; TeamPCP’s supply-chain worm campaign (Mini Shai‑Hulud) has self‑propagated across npm and PyPI, stolen developer/cloud credentials, and bypassed SLSA Build Level 3 provenance; and Drupal Core suffers a PostgreSQL-targeting SQL injection (CVE-2026-908
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- tenable_blog
- Record identifier
- 104f00d1f85d8ed9228fc972a8a539ea02b9f8bd5ab68d135f94716c39ebc95c
- Enrichment time
- 2026-05-29T08:52:21Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.