On July 21, 2026, Oracle made a major shift in its security strategy for Oracle Database, and the consequences are already being felt in Oracle Cloud Infrastructure (OCI). If you manage an Oracle Database estate, this affects you directly.
The reason: AI is changing the rules of the game
Oracle has published a note (MOS PNEWS3015) warning that new AI models are dramatically lowering the barrier to finding and exploiting software vulnerabilities. The most significant part: these models can chain together several minor vulnerabilities, none critical on their own, to build complex attacks against the entire stack, not just the application layer. That’s why protecting only the network or application layer is no longer enough; the database needs to be just as hardened.
To get ahead of this, Oracle is partnering with leading AI model vendors to find and fix vulnerabilities before they become a public problem.
Oracle’s recommendations
In response, Oracle recommends:
- Upgrading to more hardened major versions: Oracle Database 19c or the new Oracle AI Database 26ai.
- Applying the July 2026 Release Update as soon as possible (19.32 or 23.26.3), the first one tested specifically against these new AI models.
- Updating client libraries and drivers to recent versions too, including the latest version of SQL Developer.
- Moving to a monthly security patching cadence going forward, replacing the traditional quarterly cycle, so that fixes reach customers faster as new AI-discovered issues emerge.
To reduce the risk of breaking things while pushing this RU out with such urgency, Oracle states it has minimized the non-security content of 19.32.
The practical impact: OCI withdraws older versions
This is where theory turns very concrete: Oracle has removed all references to Release Updates older than 19.32 from OCI, including custom images already built on previous versions. When trying to use them, the platform shows an explicit warning stating that only images based on the latest RU are available, and that using an older image requires opening an exception Service Request with Oracle.
In other words: upgrade plans already underway toward intermediate versions (such as 19.31) are effectively blocked in Oracle’s cloud, unless an exception is granted.
And there’s more: the largest Critical Patch Update to date
Oracle also released its July 2026 Critical Patch Update yesterday, the largest one yet: over 1,400 security patches covering a similar number of distinct CVEs across hundreds of products, incorporating AI-identified findings for the first time. As noted above, Oracle is also recommending the shift to a monthly security patching cycle instead of the usual quarterly one.
What this means for our teams
- Upgrade plans currently in progress toward intermediate versions should be reviewed: if the target isn’t already the latest available RU, it likely needs to be rethought.
- It’s worth getting familiar with 19.32 as early as possible in pre-production environments, to catch any issues with time to spare.
- Moving toward a monthly patching cadence, as Oracle now recommends, will require adjusting our internal planning and change-management processes, which have historically been built around a quarterly rhythm.
- Periodic security assessments (Data Safe, AVDF, DBSAT) matter more than ever for prioritizing critical findings.
- This is likely not a one-off event: Oracle expects a continuous stream of new findings as these AI models become more widespread, along with more false positives than we’ve been used to.
Ultimately, the AI era is compressing traditional patching cycles. Staying on recent versions is no longer just a good practice, it’s becoming the only way to get real support and protection in Oracle’s cloud.
https://oraclelicensingexperts.com/blog/oracle-ecpu-vs-ocpu-pricing/