I guess you all read the announcements and predictions over the past weeks. New AI models and improvements to existing models may allow to find security issues in existing software much quicker. While this sounds alarming on one side (yes, it does), it also enables software vendors to secure their software. But in order to benefit from it, you must patch your databases against AI-enabled cybersecurity threats.

Photo by Scott Webb on Unsplash
Read the official announcements
At first, please read the official announcements released here:
- Accelerating Vulnerability Detection and Response at Oracle (3 min read – April 29, 2026)
- Take Action Today: Protect Your Oracle Database Against AI-Enabled Cybersecurity Threats (1 min read – April 30, 2026)
In essence:
“[..] Oracle has access to leading frontier AI models, including Anthropic’s Claude Mythos Preview and OpenAI’s most capable models through Trusted Access for Cyber, and we are extending our capabilities with these models to improve how quickly and effectively vulnerabilities are identified.[..]”.
What does this mean for you?
Well, you guesses it already: You must patch. On a regular basis. And of course, not only your databases but also your OS, your apps, your clients. Regular means: At least quarterly, if not monthly. This will be a challenge for some of you, I know. But before you panic, we may have some relief, at least for the database.
- Upgrade to either Oracle Database 19c or Oracle AI Database 26ai
When we ask in workshops who’s on older database releases, we still see many hands. In some countries it seems to be a tradition to stay on a database release which had been published over a decade ago. Frustratingly enough, this often applies to the most important environments. Telco billing, core banking, ATM machines, chip production, hospital environments, etc.Scary, isn’t it? I wrote about it 8 years ago – and it still is a massive problem.The good news: Upgrades never were easier. If you haven’t started, you will find a wealth of information on my team’s blogs. But you need to start now. - Move to the cloud, and especially Oracle Autonomous AI Database
When you have environments you really can’t keep up to date, especially with security patching, or where you have no resources to take care on, then consider moving them to Oracle Autonomous AI Database? Why could this be your savior? ADB gets patches on a regular basis with the most important fixes, and especially security fixes. This of course applies to Oracle Autonomous AI Lakehouse as well.Since we are the migration experts, we have the right tools. Contact us, we can help you lifting your databases quickly into ADB. If you want, even unattended. Give it a try at least – you’ll be positively surprised. And it will take away the burden of regular patching fire drills from your table. - Patch, patch, patch
I can write this easily. But I know how challenging this is. When you operate a group of Exadatas, then some stand-alone systems in addition, maybe some leftovers from over a decade ago, you can’t just say: “Oh, Wednesday, that’s patching day. Let’s do it now!” since this requires preparation, testing, sometimes even outages, downtimes. There are freeze periods, important events, super-sales, holidays. I know, it isn’t easy. But we can help you.AutoUpgrade allows you to quickly find the patches, download them to a staging server, then build the home on the target servers and patch your databases to the higher patch level. Fully unattended if you want. Scripted. Automated. Watch our Virtual Classroom Seminars #21, #27 and (when you are on MS Windows) #28.And of course, it does this at no extra license cost. Everyone has AutoUpgrade on disk already, refresh it with the newest version from oracle.com, and get started within minutes. - Stop trusting others
There is one important topic with patching: You must have access to our Support portal in order to be able to download the patches. Therefore, don’t trust vendors who promise to secure your database with a sort-of-firewall, or know everything already. Or even re-engineer our security fixes. While the latter wouldn’t be legal, none of them will be able to keep up with what Oracle is able to release. If you pay attention to security, then you will patch regularly. Which you can do either in the cloud or by downloading the necessary patches from My Oracle Support, and applying them right away.Don’t believe awesome marketing stories – and guess what, I ranted about this a few years ago as well in Virtual Patching – the biggest nonsense I’ve ever heard about. Believing always feels good – but it doesn’t secure your database.
Other changes which may affect you
As you already could read in Accelerating Vulnerability Detection and Response at Oracle, there may be monthly CSPUs available from May onward. Whether we repurpose the MRPs, or whether there will be another vehicle, I don’t know:
Oracle is expanding how security fixes are delivered to customers with a monthly Critical Security Patch Update (CSPU), starting in May 2026. CSPUs provide targeted fixes for critical security issues, allowing customers to address high-priority vulnerabilities without waiting for the next quarterly release. Each CSPU is smaller and more focused, making it easier to apply critical fixes quickly. Quarterly Critical Patch Updates will continue to include all fixes released in prior CSPUs.
Well, and this concept may sound familiar, right? We’ve had CPUs a longer while back in conjunction with PSUs and then BPs. But these new ones will be released monthly, and let us wait together for the amount of content they will include.
But you should be positively aware that MRPs (Monthly Recommended Patches) are available already on Linux for Oracle Database 19c, and those contain security fixes already on a monthly cadence.
Password Protection for older RUs
Another change you may see soon (or, according to several customers: already) is the password-protection of older Release Updates (RUs). Some of you have gone through this exercise before with the 19.29 Release Update which is only available when you open an SR and get the download password from Oracle Support. This may be the norm soon when you plan to download an older RU.
Now, it seems to be in-place already, at least for RUs before 19.30, i.e. 19.29, 19.28 and below.

Password-protection for the 19.28 Release Update – you need to open an SR to get the password
If you can’t follow this pattern of applying always the newest directly, then this may be helpful:
Use AutoUpgrade to download your patches and patch bundles on a regular basis, and store them in your own repository folder. You then can install either the newest (which is the standard in AutoUpgrade), or direct AutoUpgrade to install an older RU from this folder. But let me be very clear here: You should always and with no doubt install and use the newest RU.
Summary
We live in interesting times. Every day seems to being a new challenge, something quite unexpected, and something which sound like impossible fiction a year ago. You can’t stop that, I can’t stop it either. Be we need to adept to it. So, for you, task #1 is to upgrade to 19c and 26ai where you haven’t done already. Watch your clients, ask us if you need help or advice.
Then start setting up your automated patching with AutoUpgrade right away. Of course, you can use also FPP or the OEM package if you are licensed for either one. But do something now, don’t sit it out.
Take this serious – I didn’t write this to scare you. It is real (unfortunately).
Further Links and Information
- Virtual Classroom Seminars #21, #27 and #28
- Accelerating Vulnerability Detection and Response at Oracle (3 min read – April 29, 2026)
- Take Action Today: Protect Your Oracle Database Against AI-Enabled Cybersecurity Threats (1 min read – April 30, 2026)
- PNEWS3015
- Download the newest AutoUpgrade
- Why does your most important database run on Oracle 10.2.0.4?
–Mike
Does AutoUpgrade still need an older Java version?
AU supports Java up to 21 (the version shipped with the RDBMS kit).
Support for Java 25 will follow at some point as well.
Cheers,
Mike
Hi Mike,
I hardly dare ask – but are CPSUs also available for Windows? I would suppose not as there are neither One-offs nor MRPs for Windows, but as Oracle always stresses the importance of regular patching (and rightly so), I can’t help but wonder why an entire platform is always left out?
Cheers!
Susanne
Hi Susanne,
yes – for Win as well.
Mike
Great news. Looking forward to see this in action!
Will CSPUs be compatible with PSUs ? We made the switch from CPU application to PSU application many years ago. I am guessing that the same incompatibility that exists between PSUs and CPUs does not exist between PSUs and CSPUs.
Thanks for all the information you provide! Time after time it truly benefits us.
Hi Philip,
no worries, there won’t be such constraints as they were in the past. I hope that I can update everyone next week.
Cheers,
Mike
Hi Mike
First of all, congratulations on your blog; it’s very helpful. Secondly, I think that under this new vulnerability remediation scenario, it would be very helpful if autoupgrade also allowed us to automatically apply out-of-place patches to the grid infrastructure, in order to minimize service downtime.
Regards,
Victor Guz
Hi Victor,
thanks for the feedback – and I fully agree.
We are working on certain things but I won’t make any promises for now. It is not easy …
Cheers,
Mike
Hello Mike,
it was a pleasure listening your presentation on DBMasters event.
Today i tried to download RU 19.31, but in our company i could only reach internet through an “application proxy” which has whitelisted some oracle URL but obviously not all.
$ java -jar autoupgrade.jar -config cfg/dl1931.cfg -patch -mode download -debug
oracle.patch.config.links.PatchOptionsParser
oracle.commonx.config.links.PreCreateConfigValues
oracle.commonx.config.links.GlobalConstants
oracle.commonx.config.links.ZipMaker
oracle.commonx.config.links.ConfigPointersFileCreator
oracle.commonx.config.links.LoggerMaker
2026-05-07 11:42:31.335 DEBUG [1] oracle.commonx.config.links.ContextFinder – ContextFinder.process#123
2026-05-07 11:42:31.344 DEBUG [1] oracle.patch.config.links.PatchSettingsParser – InternalSettingsParser.process#98
2026-05-07 11:42:31.346 DEBUG [1] Created file /u01/app/autoupgrade/logs/cfgtoollogs/patch/auto/config_files/autoupg_patching.cfg – InternalSettingsParser.copyTemplateOfSettingsFile#175
AutoUpgrade Patching 26.3.260401 launched with default internal options
Processing config file …
2026-05-07 11:42:31.354 DEBUG [1] oracle.commonx.config.links.LoginFileCreator – LoginFileCreator.process#64
2026-05-07 11:42:31.361 DEBUG [1] oracle.commonx.config.links.UserConfigGlobalValidator – UserConfigGlobalValidator.process#73
global.global_log_dir=/u01/app/autoupgrade/logs
global.keystore=/u01/app/autoupgrade/keystore
dl1931.patch=RECOMMENDED
dl1931.folder=/u01/dbaautomation/RU1931
dl1931.target_version=19
dl1931.download=yes
2026-05-07 11:42:31.420 DEBUG [1] oracle.commonx.config.links.PrefixesCalculator – PrefixesCalculator.process#68
2026-05-07 11:42:31.429 DEBUG [1] oracle.commonx.config.SemanticParser – SemanticParser.analyze#58
2026-05-07 11:42:31.436 DEBUG [1] evaluateErrors 0 – CommonConfigUtils.evaluateErrors#226
2026-05-07 11:42:31.471 DEBUG [1] oracle.commonx.config.links.GlobalParametersValidator – GlobalParametersValidator.process#54
2026-05-07 11:42:31.471 DEBUG [1] validating global user-defined before action – GlobalParametersValidator.validateGlobalUserActions#71
2026-05-07 11:42:31.472 DEBUG [1] validating global user-defined after action – GlobalParametersValidator.validateGlobalUserActions#83
Loading AutoUpgrade Patching keystore
AutoUpgrade Patching keystore is loaded
2026-05-07 11:42:31.811 DEBUG [1] oracle.commonx.config.links.UserConfigCrafter – UserConfigCrafter.process#44
2026-05-07 11:42:31.812 DEBUG [1] N/A was successfully created – UserConfigCrafter.process#51
2026-05-07 11:42:31.815 DEBUG [1] oracle.commonx.config.links.SettingsMaker – SettingsMaker.process#107
2026-05-07 11:42:31.816 DEBUG [1] Crafting final settings object – SettingsMaker.process#108
There were conditions found preventing AutoUpgrade Patching from successfully running
*Downloading files
Download query failed
*Unable to tunnel through proxy. Proxy returns “HTTP/1.1 407 Proxy Authentication Required”*
what are the URL’s that needs to be accepted by our proxy in order i could use autoupgrade to download patches
br,
Manfred
Hi Manfred,
$ export https_proxy=’https://proxy.example.com:8080′
and these URLs must be whitelisted on your firewall:
https://updates.oracle.com/
https://login-ext.identity.oraclecloud.com/
https://aru-akam.oracle.com/
Cheers,
Mike
Hello,
thank you for the URL’s to whitelist, it worked until last week.
Since today (aug, 3rd) it seems there is an additional URL required and it fails.
Gold Image – 19.32.0.0.0
File: autoupgrade_linux-x86-64_19.32.0.0.0_db_home.zip / 0%
There were conditions found preventing AutoUpgrade Patching from successfully running
*Downloading files
Download failed
*Request to https://objectstorage.us-ashburn-1.oraclecloud.com failed with response code [407]*
is this new URL just temporarly or should i add objectstorage.us-ashburn-1.oraclecloud.com permanently to our whitelist ?
br,
Manfred
Hi Manfred,
we triple-checked, there was no URL/URI change – it was Ashburn before as well:
https://mikedietrichde.com/2026/07/08/autoupgrade-patching-from-zero-to-hero-part-3-download-patches/
Cheers,
Mike
Hi Mike,
In the readme file corresponding to Grid Infrastructure RU 19.31, it states:
39107855
Tomcat Release Update 19.0.0.0.0
Beginning 19.31 TOMCAT version will be deleted.
Does this mean that Tomcat will no longer be included within the Grid Infrastructure home?
Regards,
EderGuz
Yes, I think so – and there is a replacement I thinks.
Let me check with the GI folks.
Cheers,
Mike
This is an important point because AI-assisted attack methods could realistically shorten the time between vulnerability discovery and exploitation. At the same time, it’s interesting that the same technology can also improve defense and patch development. I’m curious, though, do you think organizations are currently more limited by patch availability or by their own internal delay in applying updates?
Well, both sides will be true for sure – and we will see how this manifests itself, or whether there will be a pressure decrease at a later stage (because many open issues may be fixed at some point, and not so many new ones will be found (hopefully)).
Cheers,
Mike
hi mike,
ijust downloaded the 19.31 with one off patches
this is from my config file :
patch1.platform=LINUX.X64
patch1.patch=RU:19.31,MRP,OJVM,OPATCH,DPBP,JDK,OCW,38238416,38723830,34774667,29213893
the autoupgrade downloaded both the gi ru and the db ru:
—————————————————
Downloading files to /u01/autoupgrade/patches/19.31
—————————————————
DATABASE RELEASE UPDATE 19.31.0.0.0
File: p39034528_190000_Linux-x86-64.zip – VALIDATED
OJVM RELEASE UPDATE 19.31.0.0.0
File: p38906621_190000_Linux-x86-64.zip – VALIDATED
OPatch 12.2.0.1.51 for DB 19.0.0.0.0 (Apr 2026)
File: p6880880_190000_Linux-x86-64.zip – VALIDATED
DATAPUMP BUNDLE PATCH 19.31.0.0.0
File: p39196236_1931000DBRU_Generic.zip – VALIDATED
JDK BUNDLE PATCH 19.0.0.0.260421
File: p38930593_190000_Linux-x86-64.zip – VALIDATED
GI RELEASE UPDATE 19.31.0.0.0
File: p39036936_190000_Linux-x86-64.zip – VALIDATED
ORA-600 [KTATMKREF-RS] WITH RAC ROLL OPTION FOR 19C
File: p38238416_1931000DBRU_Linux-x86-64.zip – VALIDATED
OCI: ORA-7445 [__INTEL_SSE2_STRNCMP()+379] OCCURS IN RS0I PROCESS AND INSTANCE TERMINATED.
File: p38723830_1931000DBRU_Linux-x86-64.zip – VALIDATED
ORA-7445 IN PURGE QUEUE TABLE
File: p34774667_1931000DBRU_Linux-x86-64.zip – VALIDATED
DBMS_STATS FAILING WITH ERROR ORA-01422 WHEN GATHERING STATS FOR USER$ TABLE
File: p29213893_1931000DBRU_Generic.zip – VALIDATED
why did it download the dbru if it included in the gi ru ?
thanks
Very simple answer:
It uses the DB RU to install, and not anything which is potentially added to the GI RU as well. We can’t rely on the latter, and we can’t do any sort of verification during the download interaction with MOS/ARU.
Thanks
Mike
HI Mike,
do you know when CSPUs will be included in the AutoUpgrade tool patching? I know as a workaround I could always use the patch ID and treat it like a one-off, but since it will change IDs with every iteration like OJVM and DPBP it will simple be more convenient if I simply add CSPU to the download config or if is already included in the recommended patches.
Cheers,
Daniel
Hi Daniel,
AU will support to apply CSPUs as soon as they are available. But not as DEFAULT under “RECOMMENDED” (for now).
Thanks
Mike
Hallo Mike,
haben in unseren deutschsprachigen Podcast ob ora2know auf diesen Artikel verlinkt.
https://o-wie-datenbank.podigee.io/2-oracle-patch-mythos
Danke, Oliver – hab ich mir schon angehoert 🙂
Herzliche Gruesse
Mike
I really like the AU tool, works very well with automation and should lead to more consistent and clean Oracle installs. I am curious to know if the database CSPU will increment the Oracle version number in some way. We use the RU number as part of the path for the new ORACLE_HOME that AU lays down quarterly, if we do this monthly, we will need to adjust our naming scheme.
They won’t – but I will craft a blog post this week to give more insights into CSPUs etc.
Cheers,
Mike
Hi Mike,
the Oracle Critical Security Patch Update Advisory for May 2026, just released a few hours ago, only mentions Oracle Database Server versions 23.4.0 to 23.26.2.
https://www.oracle.com/security-alerts/cspumay2026.html
Does this mean that only these versions are affected? All good for 19c 😉
Or does it mean that there will be no monthly Critical Security Patch Updates (CSPU) for Oracle Database 19c?
It would be much appreciated if you could clarify this and provide some additional insight.
And I’m also hoping that you will write a separate blog post as soon as the first CSPU in May or June is finally available.
Hi Martin,
none of the 26ai CSPU fixes were applicable to 19c, and therefore no 19c has been released.
And yes, blog post will come, no worries.
Mike
Hi Mike,
we got an password request with the new update that was released yesterday, the May 2026 for Oracle 23.26.2.
https://support.oracle.com/support/?patchId=39345754
Where can I get the password?
You need to open an SR and ask Oracle Support for the PW.
Cheers,
Mike
Hi Mike,
the password request was removed the following day and I was able to download it, so all is OK and the patch is now installed…
Thank you, Mika!
Cheers
Mike
Hello,
i would have two questions:
– The May MRP is only available for the database ? or is there also MRP for Grid Home available ?
– Autoupgrade tool is able to download such DB and GI patches, could we use AU also to download the related Oracle Unbreakable Linux Patches ?
br,
Manfred
Hi Manfred,
MRPs are for the database only.
As of now, there are no GI MRPs or GI CSPUs as far as I can see.
I happily forward your idea about OL patches to the developers. The challenge for us is often how patches are identified in the portal, and whether we can really download them.
Cheers,
Mike
Hello,
but there were GI MRPs in the past, e.g Patch 39024584: GI MRP 19.30.0.0.260317
would such kind of GI MRP’s include CSPUs also ?
br,
manfred
My bad, Manfred.
You were absolutely right. MRPs are available for GI releases 19.28, 19.30 and 19.31 as well as for 23.26.1 and 23.26.2 in May 2026.
Since there was no CSPU content on 19c, no separate CSPUs get released at the moment. And 26ai GI is available for Linux only, hence no CSPUs either.
But I am checking right now whether CSPUs will be deliverd for GI as well as soon as there is security content relevant to GI.
Cheers,
Mike