Oracle July 2026 Critical Patch Update Addresses 1235 CVEs

2026-07-28T20:52:10Z5b6e315f151406672a1077d156d789b496ef046fcf7837291a1bbc4a0719d55e
CVE-2026-15409CVE-2026-15410CVE-2026-32201CVE-2026-45659CVE-2026-55040CVE-2026-56164CVE-2026-58644CVE-2026-60137CVE-2026-63030AI coding assistantsCISAMicrosoft SharePoint ServerOracle Critical Patch UpdateSonicWall SMA 1000WordPressactive exploitationconfiguration poisoningcredential theftpre-authenticationremote code executionsupply-chain attackzero-day

What happened

Tenable’s July 2026 reporting covers multiple high-impact security developments: Oracle’s quarterly update addressing 1,235 CVEs; supply-chain attacks that poison AI coding-assistant configuration files; active exploitation of WordPress Core flaws enabling pre-authentication RCE; active exploitation of multiple on-premises Microsoft SharePoint Server vulnerabilities; and exploited SonicWall SMA 1000 zero-days that may be chained for unauthenticated RCE. The most urgent issues are the actively exploited WordPress, SharePoint, and SonicWall vulnerabilities, for which patches and mitigations are️

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
tenable_blog
Record identifier
5b6e315f151406672a1077d156d789b496ef046fcf7837291a1bbc4a0719d55e
Enrichment time
2026-07-28T20:52:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.