Why the AI-driven patch surge is rewriting the rules for ERP teams

Old-movie buffs will know the line. In Mel Brooks’ 1974 comedy classic Blazing Saddles, a band of outlaws-for-hire scoffs at the idea that they need any official credentials: “Badges? We don’t need no stinkin’ badges!” It’s funny precisely because the bravado is so obviously misplaced — of course they need the badges.

Swap “patches” for “badges,” and a lot of IT organizations have been living that same punchline this year without realizing it. “Patches? We don’t need no stinkin’ patches” was a defensible posture when critical updates arrived on a predictable quarterly clock, and teams could plan a maintenance window around them. That posture does not survive contact with 2026.

What Changed

Many of our clients have noticed a sharp jump in how often their ERP systems need patching. Oracle has moved its Critical Patch Update program from quarterly to monthly releases, and we’re seeing the same pattern from other software and operating system vendors: more out-of-band, critical-severity releases showing up with less notice.

It’s fair to ask: did quality control on this software suddenly get worse? Did a bad batch go out? Not exactly. The real driver is AI. Programs like Anthropic’s Project Glasswing have turned frontier models loose on scanning open-source and enterprise codebases for vulnerabilities, and the results have been striking — over 23,000 issues identified, with more than 90% confirmed as true positives, including flaws that had been sitting undetected in production software for five years or more. We won’t rehash the technical deep-dives on Glasswing and Mythos Preview here — plenty of others have covered that ground well — but the headline for ERP teams is simple: decades of latent technical debt is getting surfaced all at once.

As the UK’s National Cyber Security Centre put it: AI didn’t create these vulnerabilities. It lowered the cost of finding flaws that were already there. Discovery is now fast, cheap, and largely automated. Fixing them is not.

Why This Hits ERP Systems Especially Hard

For our PeopleSoft clients specifically, there’s an added wrinkle. Oracle has extended PeopleSoft support through at least 2037, so this isn’t a “the platform is going away, ride it out” situation — you’ll be patching PeopleSoft environments for a long time to come. At the same time, Oracle is reducing the official PeopleSoft Update Image cadence for HCM and FSCM from three images a year to two, starting in 2027. Campus Solutions stays at three; CRM, ELM, and Cloud Manager are unchanged.

Put those two trends together, and you get a widening gap: the routine, scheduled channel for bundled fixes is shrinking, while the volume of urgent, out-of-cycle security patches — spanning not just PeopleSoft itself, but the WebLogic application server, the underlying Oracle database, and the Linux OS beneath it — keeps climbing. You can no longer count on “wait for the next update image” as a patching strategy.

The Real Cost Is Capacity, Not Complexity

None of these patches are individually hard to apply. The problem is volume and timing. IT shops that were comfortable running quarterly update cycles — with planned testing windows and negotiated production outages — are now finding that same cycle repeating every few weeks. About the time your team finishes validating last month’s patch, the next critical one is already due. That workload doesn’t replace anything on your team’s plate; it stacks on top of it, and it’s almost always your most experienced (and most strategically valuable) people who end up pulled into patch triage instead of the roadmap work you actually hired them for.

The Cost of Standing Still

There’s also a cost to not patching, and it’s easy to underestimate if your ERP system isn’t publicly exposed. “We’re not on the internet” feels like protection, but it isn’t complete protection. An unpatched, internal-only ERP system can still be exploited by someone already inside your network — whether that’s a malicious insider or an external actor who got a foothold through a different, unrelated app and is now moving laterally because they’re “on the network.” Internal-only doesn’t mean untouchable.

Where NRC Fits

This is exactly the gap New Resources Consulting’s (NRC) Enterprise Solutions Group is built to close. Our Managed Services team can augment your existing staff to absorb this patching workload — across PeopleSoft, WebLogic, Oracle, and Linux — so your internal team isn’t the one absorbing every out-of-cycle fire drill. Our consultants average 15+ years of ERP administration experience across operating system and database platforms, and we’ve built our process around automation and streamlined testing to turn patches around quickly without cutting corners on validation.

We’re not selling a one-time cleanup sprint. The patch volume we’re seeing today isn’t a spike that settles back down — it’s the new operating tempo. What you need is sustained capacity to match it.

If your team is feeling the squeeze between patch cycles, let’s talk about what that capacity could look like for your environment. Reach out to NRC’s Enterprise Solutions Group to start the conversation.

We invite you to connect with Mike Doyle via email or LinkedIn.

Mike Doyle Bio | New Resources Consulting