Slide 8
Slide 8 text
2026/07
インフラストラクチャに対する緊急のセキュリティ脆弱性対応
通知ポリシーの変更
本ポリシーの変更の通知内容
2026/7/20より、緊急性の高いセキュリティ脆弱
性対応が必要な場合、月次インフラ・セキュリティ
メンテナンス期間外での更新を行います。
•
VM再起動なしでオンラインで実施
(事前通知はありません)
Subject: Update to Oracle Exadata Critical CVE Patching Notification Policy
Description
To protect customers against the rapidly emerging class of AI-enabled cybersecurity threats, Oracle is updating its
customer notification policy for Critical and Emergency Common Vulnerabilities and Exposures (CVEs) affecting the
Exadata infrastructure used by Oracle Exadata Database Service on Dedicated Infrastructure (ExaDB-D).
In addition to applying monthly security patches, Oracle may, in exceptional circumstances, apply critical security updates
to your Exadata infrastructure outside the scheduled monthly maintenance window to address urgent security
vulnerabilities. These updates are applied online and do not require a reboot of the virtual machines (VMs).
Effective July 20, 2026, to minimize the window of exposure of your infrastructure to these vulnerabilities, Oracle will no
longer send separate customer notifications prior to applying these required Critical and Emergency CVE updates.
No action is required from your side.
Oracle remains committed to maintaining the security, stability, and availability of the Oracle Exadata Database Service on
Dedicated Infrastructure.
Refer - Overview of Monthly Security Maintenance.
OCID xxxxxx
Reference ticket number xxxxxx
Type Information
Affected service Oracle Exadata Database Service on Dedicated Infrastructure
Region Japan Central (Osaka)
Created Jul 17, 2026, 11:00:58 UTC
Updated Jul 17, 2026, 11:10:12 UTC
User status Unread
8
Copyright © 2026, Oracle and/or its affiliates