
April 2026 CPU: 8 DB patches, 4 unauth + remote. The sleeper: CVE-2026-35229 — Java VM via Oracle Net, zero creds. Hits 19.3–19.30 and 21.3–21.21. If you don't use Java VM, just remove it. Patching attack surface you don't run is wasted effort. #OracleDBA
Post summary
The post highlights CVE-2026-35229, a remote unauthenticated vulnerability in Oracle Java VM via Oracle Net, and recommends applying database patches and disabling Java VM to mitigate the risk.


