Oracle May 2026 Critical Security Patch Update Addresses 35 CVEs

2026-05-29T08:52:21Z104f00d1f85d8ed9228fc972a8a539ea02b9f8bd5ab68d135f94716c39ebc95c
35 CVEsCI/CD compromiseCVE-2026-9082DrupalEXPOSURE 2026Mini Shai-HuludOracle CSPU May 2026PostgreSQLPyPISLSA Build Level 3SQL injectionTeamPCPTenable One Open Connectorcredential theftcritical patchesexposure managementnpmnpm download pumpingpackage ecosystemprovenance bypassself-propagating wormsupply chain attack

What happened

Tenable published multiple security updates and research briefings in May 2026: Oracle's May 2026 Critical Security Patch Update (CSPU) fixes 35 CVEs across five product families, including 11 critical issues; Tenable researchers disclosed a new npm deception technique (“download pumping”) that inflates download metrics to hide malicious packages; TeamPCP’s supply-chain worm campaign (Mini Shai‑Hulud) has self‑propagated across npm and PyPI, stolen developer/cloud credentials, and bypassed SLSA Build Level 3 provenance; and Drupal Core suffers a PostgreSQL-targeting SQL injection (CVE-2026-908

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
tenable_blog
Record identifier
104f00d1f85d8ed9228fc972a8a539ea02b9f8bd5ab68d135f94716c39ebc95c
Enrichment time
2026-05-29T08:52:21Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Oracle May 2026 Critical Security Patch Update Addresses 35 CVEs · Baitaphish