top of page

LATEST INSIGHTS

Expert insights across your SaaS environment

Blogs and papers from the SAASiQ team on enterprise SaaS, cloud and AI.

Oracle Moves to Monthly Security Patches as AI Speeds Up Vulnerability Discovery

Writer: SAASiQ.ai
SAASiQ.ai
May 15
6 min read

Updated: 6 days ago

Title: Oracle Moves to Monthly Security Patches as AI Speeds Up Vulnerability Discovery

Date: 15 May 2026

Type: Blog

Author: SAASiQ (contact@saasiq.ai)

Word count: 1438 words

Reading time: 6 min

Published: 15-05-2026


Oracle said on 29 April that it will issue security patches every month as well as every quarter, because frontier AI models are finding software vulnerabilities faster than a quarterly cycle can fix them. The first monthly Critical Security Patch Update is due on 28 May. On 30 April Oracle told database customers to move to 19c or 26ai and keep current with Release Updates, and on 6 May OpenAI released a networking protocol, MRC, that already runs on Oracle's Acceleron network at the Stargate site in Abilene, Texas.


Monthly patches from 28 May

Oracle introduced the Critical Security Patch Update (CSPU) in a post on its security blog on 29 April, 'Accelerating Vulnerability Detection and Response at Oracle'. Each CSPU is smaller and more focused than the quarterly Critical Patch Update, and carries targeted fixes for critical issues so that customers do not have to wait for the next quarter. The quarterly CPU continues in January, April, July and October, and takes in the fixes from the monthly releases before it.


The first CSPU is due on Thursday 28 May. After that, CSO Online reported on 5 May, the monthly releases move to the third Tuesday of the month, starting on 16 June. That is the day Oracle already uses for its quarterly updates, and a week after Microsoft, SAP and Adobe publish theirs.


For a sense of volume, the April CPU, released on 21 April, contained 481 security updates for 241 unique CVEs across 28 Oracle product families, by Tenable's count. The monthly releases carry critical fixes in the months between those quarterly bundles.


The AI models behind the change

Oracle says it has access to Anthropic's Claude Mythos Preview and to OpenAI's most capable models through OpenAI's Trusted Access for Cyber programme, and that it runs them on OCI as part of its vulnerability detection and code analysis. It applies them across Oracle-developed software and services, Oracle Health, and the open-source components it builds and uses in its products. Oracle linked the monthly cycle directly to the faster pace at which AI is now finding vulnerabilities.


The database team followed on 30 April with 'Take Action Today: Protect Your Oracle Database Against AI-Enabled Cybersecurity Threats'. It says the April and July 2026 Release Updates are the first to include security hardening informed by testing with frontier models, and that it is not technically feasible to backport all the new fixes to older database versions or older Release Updates. Oracle's advice is to move to one of the two Long Term Support releases, Oracle Database 19c or Oracle AI Database 26ai, apply the April updates (RU 19.31 or RU 23.26.2) and stay current from there. It also asks customers to isolate databases on the network and not to expose them directly to the public internet.


The April updates themselves were late. Mike Dietrich, Oracle's product manager for database upgrades, wrote on his blog that as of 27 April both would reach Linux on 1 May, with 19.31 for other platforms following on 15 May.


Who applies the patches

Oracle's announcement splits the work by deployment. In Oracle-managed services the protections are applied automatically. In customer-managed deployments, on-premises or on OCI, Oracle finds the vulnerabilities and ships patches for supported products, and the customer remains responsible for testing and applying them.


On OCI's own database services the line falls in different places. Autonomous AI Database is patched by Oracle. On Exadata Database Service and Exadata Cloud@Customer, Oracle maintains the infrastructure, but Oracle's documentation makes the customer responsible for patching the Oracle Database and Grid Infrastructure homes and the guest operating system in its VMs, with tools such as dbaascli. So a customer running Exadata in OCI faces the same monthly decision as one running it in its own data centre. Fusion Applications, as SaaS, sit on the Oracle-managed side.


E-Business Suite estates are mostly customer-managed. In October 2025 Oracle issued a Security Alert for CVE-2025-61882, a flaw in EBS 12.2.3 to 12.2.14 that could be exploited remotely without authentication and scored 9.8 out of 10. Security researchers linked it to a data-theft campaign by affiliates of the Cl0p extortion group, reportedly under way since at least August 2025.


Access controls for agents in the database

Oracle announced Deep Data Security on 24 March, at its AI World Tour event in London, as a built-in feature of Oracle AI Database 26ai. It moves authorisation into the database itself. The identity, roles and attributes of an end user, or of an agent acting for one, are passed to the database at runtime, and the database applies its policies to every query and writes audit records of the activity.


The model has three parts. An end user, created with CREATE END USER, is a database identity that owns no objects. A data role groups the policies for a set of end users and switches on when they authenticate. A data grant, written in SQL, says which operations are allowed and which rows qualify, and the controls reach down to columns and individual cells, with masking of sensitive values. A manager and an employee who put the same question to the same agent get different rows back, and the agent does not have to write any filter.


The case Oracle makes is about agents that generate their own SQL. If prompt injection pushes an agent into asking for data its user should not see, a policy enforced in the database still applies. Deep Data Security is a 26ai feature, so customers who stay on 19c keep the older tools for this, such as Virtual Private Database and Real Application Security.


Acceleron and the MRC protocol

Acceleron is OCI's networking architecture for large GPU clusters. Oracle described it at Oracle AI World in October 2025, alongside OCI Zettascale10, a cluster design that Oracle said would initially target deployments of up to 800,000 NVIDIA GPUs and that underpins the supercluster built with OpenAI in Abilene as part of Stargate. Its multiplanar design runs several physically independent network planes, so a fault in one plane does not take down the whole fabric.


Multipath Reliable Connection (MRC) is an RDMA transport protocol that OpenAI developed over about two years with AMD, Broadcom, Intel, Microsoft and NVIDIA, and released as an open specification through the Open Compute Project. It spreads the packets of a single connection across many paths at once, uses SRv6 source routing, and detects and routes around failures in microseconds. OpenAI said MRC already runs on its largest NVIDIA GB200 training clusters, including the OCI site at Abilene and Microsoft's Fairwater supercomputers, and that the design can connect more than 100,000 GPUs with two tiers of Ethernet switches, where conventional 800Gb/s networks need three or four.


NVIDIA's announcement on 6 May said both Fairwater and OCI's Abilene data centre rely on MRC. For customers renting large amounts of GPU capacity on OCI, the practical effect is on how a long training job behaves when part of the network fails. OpenAI gave one example: during a recent frontier training run it rebooted four tier-1 switches without interrupting training.


Models and sovereign deployments

OCI Generative AI added xAI's Grok 4.3 on 1 May, a reasoning model with a one-million-token context window, according to Oracle's release notes. The other additions in the first half of May were Cohere Rerank 4 and mixed text and image input for Cohere Embed 4, both on 9 May, and a new region in Abu Dhabi on 5 May.


SoftBank Corp. is taking OCI services into its own data centres. On 16 April it said it would roll out generative AI services from June 2026 using Sarashina, the Japanese large language model built by its subsidiary SB Intuitions, on Cloud PF Type A, its cloud built on Oracle Alloy. Cloud PF Type A offers more than 200 OCI services, including OCI Enterprise AI, from SoftBank's own data centres, opening in eastern Japan in April 2026 and western Japan in October 2026. SoftBank runs the infrastructure itself, so data and systems stay in Japan.


The next dates

SAASiQ's view is that customers running their own Oracle databases or E-Business Suite should decide now which systems take the monthly CSPUs and which stay on the quarterly cycle, starting with anything that can be reached from the internet. For databases, Oracle's stated baseline is 19c or 26ai on the April Release Update, and customers on older releases should read the 30 April note on backports before planning around the monthly updates.


The first CSPU is due on 28 May, the second on 16 June, and the July quarterly Critical Patch Update on 21 July.

SAASiQ - Intelligent Solutions for SaaS ©

Optimise your SaaS licences and software subscriptions with SAASiQ

bottom of page