Now Playing: “New Sensation” — INXS
When I worked in radio, a new-release day meant something entirely different than it does for me today.
It meant new music arriving at the station. A new single. A new album. Something we had not played before and were anxious to hear.
While looking through one of my playlists recently, I came across “New Sensation” by INXS, from their Kick album. The song eventually reached No. 3 on the Billboard Hot 100 in 1988. View Billboard’s INXS chart history.
That title seemed especially appropriate this month.
As I write this on August 18, 2026, “new-release day” for me means logging into My Oracle Support and finding out what the latest security releases mean for the PeopleSoft environments I support.
And these days, release day comes around a lot more often.
From Quarterly to Monthly
For years, PeopleSoft administrators became accustomed to Oracle’s quarterly Critical Patch Update schedule: January, April, July, and October.
You knew the dates. You planned for them. You downloaded the patches, reviewed the documentation, scheduled development and test environments, worked through change control, and eventually moved the updates into Production.
I will admit that I have always enjoyed patching.
There is something satisfying about getting the latest software into an environment, watching the patches apply successfully, bringing everything back online, and seeing your validation checks come back clean.
When it all works the way it is supposed to, it is a pretty good feeling—for the administrator and for the customer.
In 2026, however, that familiar rhythm changed.
Oracle introduced the Critical Security Patch Update, or CSPU, to complement the traditional quarterly CPU. After the initial CSPU in May, Oracle now provides a security release on the third Tuesday of every month: CPUs in January, April, July, and October, and CSPUs in February, March, May, June, August, September, November, and December. Oracle publishes the current schedule here.
Suddenly, the quarterly patch calendar has become a monthly one.
I may need to start looking at that third Tuesday of the month before I make too many plans.
2026 Has Already Shown Why
It did not take long to see why Oracle was moving toward a more frequent security cadence.
The first CSPU arrived in May. Then, on June 10, Oracle issued an out-of-band Security Alert addressing CVE-2026-35273 in PeopleSoft PeopleTools. Oracle rated the vulnerability at 9.8 and warned that successful exploitation could result in remote code execution. The alert listed supported PeopleTools releases 8.61 and 8.62. Oracle’s June 10 Security Alert is available here.
Oracle’s immediate mitigation also brought PSEMHUB, the PeopleSoft Environment Management Hub, into the spotlight. Oracle recommended disabling PSEMHUB across PeopleTools releases and noted that doing so would not affect normal day-to-day PeopleSoft operations. Customers using its File Deploy functionality for application patching could instead deploy those files manually. For many PeopleSoft administrators, it also raised an interesting question: why was a component that often wasn’t being actively used still deployed in so many environments?
The story quickly became more than a theoretical security concern. Tenable later reported that CVE-2026-35273 had been exploited in the wild as a zero-day by the ShinyHunters extortion group. The campaign affected more than 100 organizations globally and had a significant impact on higher education in the United States. Tenable’s analysis of the June CSPU and ShinyHunters activity can be found here.
Only six days after Oracle’s Security Alert, the June CSPU arrived. Across Oracle’s affected product families, the release contained 245 security updates addressing 243 unique CVEs. For PeopleSoft specifically, Oracle listed 11 new security patches, seven of which could be exploited remotely without requiring user credentials. Oracle’s June 2026 CSPU advisory is available here.
Then came the normal July quarterly CPU.
And now, four weeks later, we are back again for the August CSPU.
That is quite a change from planning security maintenance four times per year.
What August Actually Delivered
Oracle released the August 2026 CSPU on August 18, and the final numbers are certainly eye-catching.
Across the product families covered by the release, Oracle lists 943 new security patches. The August CSPU advisory can be reviewed here.
For PeopleSoft specifically, the August CSPU includes 15 new security patches, seven of which may be remotely exploited without authentication, with a maximum CVSS 3.1 Base Score of 9.8. The affected supported products include PeopleTools versions 8.61 through 8.63, along with several PeopleSoft application components.
It is also worth remembering what “supported versions” means in a security advisory. Oracle notes that product releases outside Premier or Extended Support are not tested for the vulnerabilities addressed by a CSPU and that earlier versions of affected releases are likely to be affected as well. An older PeopleTools release disappearing from the current risk matrix should therefore not be interpreted as that release suddenly becoming immune to newly discovered vulnerabilities.
Oracle Fusion Middleware is another significant part of the August release. The CSPU contains 262 new Fusion Middleware security patches, 182 of which Oracle says may be remotely exploited without authentication. The overall Fusion Middleware risk matrix reaches a maximum CVSS score of 10.0, and WebLogic Server is among the affected products.
Java SE is also part of the August CSPU, with five new security patches, four of which Oracle identifies as remotely exploitable without authentication. The highest CVSS score in the Java risk matrix is 7.8.
I also had an opportunity to apply the August updates to PeopleSoft environments running on both Windows and Linux. In my testing, WebLogic received an updated Stack Patch Bundle, while Java moved from 21.0.12 to the minor 21.0.12.1 release. OPatch itself remained at the same level. The updates applied successfully, and the environments came back online cleanly.
My Oracle Support was also showing new PeopleTools 8.62.12 and 8.61.22 patches. The remaining piece I’ll be watching is the August PeopleTools infrastructure DPK, which will show how Oracle packages the updated middleware stack for PeopleSoft.
The security advisory may arrive on the third Tuesday, but for PeopleSoft administrators, release day does not necessarily end there. Supporting infrastructure packages can follow in the days afterward, extending the evaluation and testing cycle.
The numbers are important, but I think the bigger story is what this new cadence means operationally.
The Other Side of Faster Security Releases
I recently read a discussion among fellow PeopleSoft administrators that really struck a chord with me.
Those conversations have also made one thing clear: I am not alone in feeling some degree of “patch fatigue.” The increased cadence may speed up how quickly security fixes become available, but it also puts more pressure on the teams responsible for testing, staging, and safely deploying them.
The point is that today’s security cadence cannot be considered one vendor at a time.
Oracle is releasing patches. Operating system vendors are releasing patches. Network and security products are being updated. Database software is being patched. Middleware is being patched. Other enterprise applications have their own security calendars.
All of those changes eventually arrive at the same place: the teams responsible for testing, staging, and deploying them.
That is the part of this new monthly cadence that I think deserves more discussion.
Security teams understandably want vulnerabilities addressed as quickly as possible. Administrators want exactly the same thing.
But releasing a patch and safely deploying a patch are not the same task.
Before a security update reaches a PeopleSoft Production environment, someone needs to determine what applies. Someone has to download it and review the prerequisites. Development and test environments need to be patched. Application functionality needs to be validated. Process Schedulers, Integration Broker, web servers, and application servers need to be checked. Database and operating system teams may also need to be involved.
Then there are change control meetings, business schedules, and Production maintenance windows.
That takes time.
The challenge with a monthly cadence is that one testing cycle can begin to overlap the next release. A team may still be moving the previous month’s updates toward Production when another advisory appears.
The speed at which a customer can safely absorb change has therefore become part of the security discussion itself.
Moving too slowly creates exposure.
Moving too quickly without proper testing can create a different kind of risk.
Finding the balance between those two is becoming an increasingly important part of the PeopleSoft administrator’s job.
Patching Is Becoming a Standing Process
One lesson I am already taking from 2026 is that organizations may need to stop treating security patching as a quarterly project.
It is becoming a standing operational process.
That may mean reserving recurring testing windows rather than rebuilding the process from scratch for every security release. It may mean having repeatable validation checklists ready to go. It may mean clearly identifying ownership between PeopleSoft, database, operating system, networking, and security teams before the next advisory arrives.
It also makes good documentation even more important.
- What exact PeopleTools release are we running?
- What WebLogic and Java levels are installed?
- Which patches are already present?
- Which environments have been updated?
- What did we test after the last maintenance cycle?
The less time an administrator spends rediscovering the environment every month, the more time there is to evaluate and safely deploy the actual security fixes.
Automation has also become an even larger part of this conversation. Scripts that once made quarterly maintenance more convenient are becoming increasingly important when that same work may occur every month. Repeatable automation for backing out prior Java and WebLogic patches, applying new ones, and validating the environment afterward can reduce both the time required and the opportunity for human error.
The Next Release Is Already on the Calendar
Another difference with this new cadence is that there isn’t really a finish line anymore.
After the August 18 CSPU, Oracle’s next scheduled security release is the September 15 CSPU, followed by the next quarterly CSPU on October 20. Another CSPU arrives on November 17, with the final scheduled CSPU of 2026 on December 15.
And the cycle continues.
I still look forward to seeing what is included in a new release. I still enjoy applying the patches, bringing the environment back online, and seeing everything working properly afterward. That part has not changed.
INXS gave us “New Sensation” back in 1988. PeopleSoft administrators have a different kind of new-release day in 2026.
The sensation of getting everything patched and seeing those validation checks come back green is still a good one.
The rhythm is just a lot faster now.
And apparently, so is the record.
From NRC’s Enterprise Solutions Group
Mike’s experience above is one we’re hearing from PeopleSoft and ERP teams everywhere: the shift from a quarterly to a monthly, sometimes faster, security cadence is straining even well-run environments. That’s exactly the gap NRC’s Enterprise Solutions Group built Rapid Patch Response to close: ongoing, coordinated patch management across PeopleSoft, WebLogic, Oracle, and Linux, with turnaround tailored to your team’s risk tolerance and change-management process.
If your team is feeling the squeeze between release cycles, reach out to NRC’s Enterprise Solutions Group to talk about what sustained coverage could look like for your environment — or download the one-page overview for the details.



