Oracle released its second quarterly edition of this year’s Critical Patch Update. The update received patches for 309 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 84, constituting about 27% of the total patches released. Oracle MySQL and Oracle Fusion Middleware followed, with 40 and 36 security patches.
228 of the 309 security patches provided by the April Critical Patch Update (about 74%) are for non-Oracle CVEs, such as open-source components included and exploitable in the context of their Oracle product distributions.
This batch of security patches received 15 updates for Oracle Database products. The following is the product-wise distribution:
- Six new security updates for Oracle Database Server with a maximum reported CVSS Base Score of 8.8.
- One of these updates applies to client-only deployments of the Oracle Database.
- One new security update for Oracle Application Express with a maximum reported CVSS Base Score of 9.0.
- One new security update for Oracle Blockchain Platform with a maximum reported CVSS Base Score of 6.5.
- Five new security updates for Oracle GoldenGate with a maximum reported CVSS Base Score of 7.5.
- One new security update for Oracle NoSQL Database with a maximum reported CVSS Base Score of 3.7.
- One new security update for Oracle REST Data Services with a maximum reported CVSS Base Score of 6.1.
In these security updates, Oracle has covered product families, including Oracle Database Server, Oracle Application Express, Oracle Blockchain Platform, Oracle GoldenGate, Oracle NoSQL Database, Oracle REST Data Services, Oracle Commerce, Oracle Communications Applications, Oracle Communications, Oracle Construction and Engineering, Oracle E-Business Suite, Oracle Enterprise Manager, Oracle Financial Services Applications, Oracle Fusion Middleware, Oracle Analytics, Oracle HealthCare Applications, Oracle Hospitality Applications, Oracle Hyperion, Oracle Insurance Applications, Oracle Java SE, Oracle JD Edwards, Oracle MySQL, Oracle PeopleSoft, Oracle Retail Applications, Oracle Siebel CRM, Oracle Supply Chain, Oracle Utilities Applications, Oracle Virtualization.
Qualys QID Coverage
Qualys has released the following QIDS mentioned in the table:
QIDs | Title |
20487 | Oracle Database 21c Critical Patch Update – July 2025 |
20488 | Oracle Database 19c Critical Patch Update – July 2025 |
20490 | Oracle MySQL Server July 2025 Critical Patch Update (CPUJUL2025) |
383578 | Oracle Java Standard Edition (SE) Critical Patch Update – July 2025 (CPUJUL2025) |
383580 | Oracle Coherence July 2025 Security Patch Update (CPUJUL2025) |
383586 | Oracle Managed Virtualization (VM) VirtualBox Multiple Security Vulnerabilities (CPUJUL2025) |
296127 | Oracle Solaris 11.4 Support Repository Update (SRU) 83.195.1 Missing (CPUJUL2025) |
87583 | Oracle WebLogic Server Multiple Vulnerabilities (CPUJUL2025) |
Note: The table will be updated with additional QIDs once released.
Notable Oracle Vulnerabilities Patched
Oracle Communications
This Critical Patch Update for Oracle Communications received 84 security patches. Out of these, 50 vulnerabilities can be exploited over a network without user credentials.
CVE-2024-25638, CVE-2025-48734, CVE-2024-47606, CVE-2024-1135, CVE-2025-23016, CVE-2025-27363, and CVE-2023-27349 in different Oracle Communications products have high severity ratings.
Oracle MySQL
This Critical Patch Update for Oracle MySQL received 40 security patches. Out of these, three vulnerabilities can be exploited over a network without user credentials.
CVE-2024-9287 and CVE-2025-32415 in MySQL Workbench have high severity ratings. An attacker may exploit these vulnerabilities without privileges in a low-complexity network attack.
Oracle Fusion Middleware
This Critical Patch Update for Oracle Fusion Middleware received 36 security patches. Out of these, 22 vulnerabilities can be exploited over a network without user credentials.
CVE-2025-31651 and CVE-2024-52046 in different Oracle Fusion Middleware products have critical severity ratings with a CVSS score of 9.8. A remote attacker may exploit these vulnerabilities without privileges in a low-complexity network attack.
Oracle Communications Applications
This Critical Patch Update for Oracle Communications Applications received 29 security patches. One of the vulnerabilities can be exploited over a network without user credentials.
CVE-2025-48734 and CVE-2024-56406 in different Oracle Communications Applications products have high severity ratings with a CVSS score of 8.8 and 8.6. A remote attacker may exploit these vulnerabilities without privileges in a low-complexity network attack.
Oracle Financial Services Applications
This Critical Patch Update for Oracle Financial Services Applications received 18 security patches. Out of these, 13 vulnerabilities can be exploited over a network without user credentials.
CVE-2025-48734 impacting different Oracle Financial Services Applications products has high severity ratings with a CVSS score of 8.8. A remote attacker may exploit these vulnerabilities without privileges in a low-complexity network attack.