Oracle has announced its policy to accelerate the update patch cycle for Java, which has previously been provided every 3 months, to provide security patches every 1 months. This patch delivery has already commenced as of last month (August 2026).
Oracle to Begin Monthly Java Security Patches to Counter Faster AI-Driven Vulnerability Discovery
This article is a translation. Read the Japanese original
Traditionally, in addition to new version releases every six months, Java has provided updates called CPU (Critical Patch Update) every 3 months in January, April, July, and October. However, in response to the fact that the emergence of AI has enabled the discovery of vulnerabilities at a faster pace than before, and that vulnerability remediation can also be accelerated with AI assistance, Oracle is taking measures to adapt.
The newly provided monthly patches are called "CSPU (Critical Security Patch Updates)" and will provide fixes for critical security issues. Depending on the severity and nature of the vulnerabilities being addressed, users can choose to apply the monthly CSPU immediately or wait for the comprehensive updates via the traditional 3-month CPU.
While monthly patch delivery will allow Java vulnerabilities to be fixed earlier, it will require companies to make patch application decisions more frequently.
Sources
- Oracle begins monthly Java security patches, citing AI's acceleration of vulnerability discovery (Publickey, 2026-09-15)