Oracle January 2026 CPU Delivers 337 Security Patches Including CVE-2025-66516 & CVE-2026-21962
ID: 563706a2-a8d3-577c-9be9-5806c6ef515c
STIX ID: report--563706a2-a8d3-577c-9be9-5806c6ef515c
Feed Name: SOCRadar Blog
Oracle's January 2026 Critical Patch Update delivers 337 patches (about 230 unique CVEs) across more than 30 product families, including multiple critical, remotely exploitable vulnerabilities—most notably CVE-2025-66516 (Apache Tika) and CVE-2026-21962 (WebLogic Server Proxy Plug-in). While Oracle reported no known zero-days or active exploitation at release, the large number of remotely exploitable issues and shared third-party library impacts make rapid prioritization and patching of internet-facing and high-risk systems essential.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
