Oracle July 2026 Critical Patch Update Addresses 1235 CVEs
2026-07-28T20:52:10Z•5b6e315f151406672a1077d156d789b496ef046fcf7837291a1bbc4a0719d55e
CVE-2026-15409CVE-2026-15410CVE-2026-32201CVE-2026-45659CVE-2026-55040CVE-2026-56164CVE-2026-58644CVE-2026-60137CVE-2026-63030AI coding assistantsCISAMicrosoft SharePoint ServerOracle Critical Patch UpdateSonicWall SMA 1000WordPressactive exploitationconfiguration poisoningcredential theftpre-authenticationremote code executionsupply-chain attackzero-day
What happened
Tenable’s July 2026 reporting covers multiple high-impact security developments: Oracle’s quarterly update addressing 1,235 CVEs; supply-chain attacks that poison AI coding-assistant configuration files; active exploitation of WordPress Core flaws enabling pre-authentication RCE; active exploitation of multiple on-premises Microsoft SharePoint Server vulnerabilities; and exploited SonicWall SMA 1000 zero-days that may be chained for unauthenticated RCE. The most urgent issues are the actively exploited WordPress, SharePoint, and SonicWall vulnerabilities, for which patches and mitigations are️
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- tenable_blog
- Record identifier
- 5b6e315f151406672a1077d156d789b496ef046fcf7837291a1bbc4a0719d55e
- Enrichment time
- 2026-07-28T20:52:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.