☕ This Week’s Focus
Patch fatigue is a staffing problem, not a patching problem.
Two years ago, an Oracle shop planned around four events a year: January, April, July, October. You knew the dates, you booked the change windows, you got through it. Since May, Oracle has layered monthly Critical Security Patch Updates on top of the quarterly CPUs — roughly a dozen patch events a year instead of four. The August CSPU alone carried 943 security updates.
Nobody’s DBA headcount tripled to match. That’s the whole story. Fatigue isn’t a discipline failure or a maturity-model gap; it’s arithmetic. Three times the events, the same two people, the same change advisory board that meets every other Thursday. And this week Oracle handed PeopleSoft customers a 9.8 to prove the point.
Let’s get into it.
🔐 The August CSPU: What You Actually Have to Do
🔗 Oracle Critical Security Patch Update August 2026 addresses 925 CVEs (Tenable) https://www.tenable.com/blog/oracle-august-2026-critical-security-patch-update-cspu-addresses-925-cves
Released August 18: 925 unique CVEs in 943 security updates across 23 product families, 154 of them rated critical. Compare that to the June CSPU — 243 CVEs, 245 patches, 11 product families. A nearly fourfold jump in a release that is supposed to be the small one between quarterly CPUs.
🔗 CVE-2026-60821 — PeopleTools Business Interlink, CVSS 9.8 https://notcve.org/cve/CVE-2026-60821
This is the one to read first. Unauthenticated, network-accessible over HTTP, low attack complexity, full takeover of PeopleSoft Enterprise PeopleTools. Affected: 8.61 through 8.63 — including the release Oracle shipped last month.
My read: Business Interlink is legacy plumbing most sites forgot they had enabled. That is exactly the profile of CVE-2026-35273 in June: an old component, still listening, still reachable. If your PeopleTools tier answers HTTP from anywhere untrusted, treat this as a same-week job, not a next-cycle job.
🔗 CVE-2026-60879 — Configuration Manager, CVSS 8.8 (Tenable) https://www.tenable.com/cve/CVE-2026-60879
A low-privileged authenticated user, over SQL, to complete PeopleTools takeover. Versions 8.61-8.63 again. The companion, CVE-2026-60856 (CVSS 7.4, Install and Packaging, unauthenticated but high complexity), and CVE-2026-60884 (Panel Processor, scope-changing) round out the batch.
🔗 CVE-2026-60856 (Tenable) https://www.tenable.com/cve/CVE-2026-60856
My read: 60879 is the item that should change behavior, not just patch schedules. “Low privileged” means any ordinary account that got a role it never needed is now a takeover path. Patching closes this instance. Least privilege closes the class. That’s Thursday’s post.
🔗 Oracle Critical Patch Update, August 2026 Security Update Review (Qualys) https://blog.qualys.com/vulnerabilities-threat-research/2026/08/19/oracle-critical-patch-update-august-2026-security-update-review
Useful if you scan: QID 388371 covers the PeopleTools multi-vuln set, 388372 VirtualBox, 87617 WebLogic, 20609 Database 19c. Detection first, evidence second, argument with your CAB third.
🧰 Oracle Is Re-Timing the Treadmill (Slowly)
🔗 PeopleSoft aligns HCM and FSCM update cadence with customer adoption starting in 2027 (Oracle) https://blogs.oracle.com/peoplesoft/peoplesoft-aligns-hcm-and-fscm-update-cadence-with-customer-adoption-starting-in-2027
From 2027, HCM and FSCM drop from three update images a year to two. Campus Solutions stays at three; Cloud Manager, ELM and CRM are unchanged. Oracle’s stated reason is honest: most customers get current every 12-18 months and were never consuming all three.
My read: This is Oracle admitting the adoption arithmetic on the functional side — and it makes the security side stand out more sharply. Feature delivery slows down to match what teams can absorb; security delivery speeds up regardless. Those two curves now point in opposite directions, and your staffing plan has to serve both.
🔗 PeopleSoft Update Image containers: PUM deployment just changed (PeopleSoft Career) https://blog.peoplesoftcareer.com/peoplesoft-update-image-containers/
FSCM Update Image 57 is the first PUM you can stand up with Podman instead of VirtualBox — pre-built images, one compose command — and Oracle stated in the same breath that the VirtualBox DPK is expected to be retired in future releases.
My read: This is the one piece of genuine labor relief on the table. A PUM environment that comes up in minutes instead of a morning is real capacity given back to a two-person team. It costs you Podman fluency now instead of under deadline later.
🔗 PeopleTools 8.63: AI, security, and upgrade planning (SmactWorks) https://www.smactworks.com/insights/blogs/2026/08/peopletools-8-63-guide.html
8.63 went GA on OCI July 29 via Cloud Manager Image 22; on-premises is still “to follow.” Highlights that matter for this week’s theme: SAML 2.0 and TOTP two-factor, Customization Groups (cross-reference your customizations against delivered PUM maintenance), Log Analyzer, and webhooks. Also the release carrying three of this month’s CVEs — being current is not the same as being safe.
💸 The Arithmetic Behind the Staffing
🔗 Oracle spent $55.7 billion on data centres in a single year (The Next Web) https://thenextweb.com/news/oracle-q4-fy2026-capex-55-billion-ai-data-center-openai
FY2026 capex came in at ~$55.7B against $50B guidance, with FY2027 net outlay guided to ~$70B and reported capex expected $20-25B higher. Remaining performance obligations: $638B. Q1 FY2027 results are expected September 8.
🔗 Oracle Cloud Infrastructure revenue up 93% as capex keeps climbing (DCD) https://www.datacenterdynamics.com/en/news/oracle-cloud-infrastructure-revenue-up-93-as-firms-capex-keeps-climbing/
🔗 Oracle cuts up to 30,000 jobs globally, putting enterprise support and roadmaps at risk (CIO) https://www.cio.com/article/4153113/oracle-cuts-up-to-30000-jobs-globally-putting-enterprise-support-and-roadmaps-at-risk.html
The CIO piece names the failure mode precisely: not an outage, but “unevenness that creeps in quietly — slower escalation handling, thinner backline expertise, more handoffs.” Ask your account team for named support-coverage continuity and confirmation that release commitments hold for the next two quarters. Vague answers are themselves the answer.
🔗 The 2026 Data Infrastructure Survey (DataStrike) https://www.datastrike.com/blogs/the-2026-data-infrastructure-survey-why-rising-budgets-arent-solving-its-biggest-challenges
74% of IT organizations expect budget increases, yet only about a third employ dedicated DBAs — and over half of those run on one or two people. 60% now lean on managed service providers, up from 26% a year ago.
My read: That is the patch-fatigue equation stated in someone else’s data. Budget is not the constraint; hours from people who know your estate are. If you are going to buy your way out, buy hours, not licenses.
🤖 The AI-vs-ERP File
🔗 Agentic ERP won’t scale until CIOs control the proof, the price, and the portability (Forrester) https://www.forrester.com/blogs/agentic-erp-wont-scale-until-cios-control-the-proof-the-price-and-the-portability/
Only 7% of ERP decision-makers run a single instance. Agents inherit every regional variant and acquired system in the estate, and 65% of adopters already rate their data accuracy as “complex.”
🔗 AI is moving faster than enterprise systems can adapt (ERP Today) https://erp.today/ai-erp-transformation-enterprise-systems-gap/
My read: Every agentic-ERP pitch assumes a clean identity and permission model underneath it. Most PeopleSoft estates do not have one — see CVE-2026-60879. Before you let an agent act inside PeopleSoft, you need to be able to say precisely what a low-privileged account can reach. Almost nobody can.
💬 Aaron’s Take
The fix for patch fatigue is not a better attitude toward patching. It’s three concrete things:
Stop treating each CSPU as a project. One standing runbook, a fixed monthly window already on the calendar for the rest of 2026 (next CSPUs: Sept 15, Nov 17, Dec 15), and a pre-approved emergency path for anything ≥9.0. Approval latency, not patch application, is where the weeks go.
Buy hours, not tools. If you have one DBA and twelve patch events a year, that is a staffing decision someone made without saying it out loud. Say it out loud, with the CVSS scores attached.
Move the PUM lab to containers now. Image 57 on Podman is the only item this month that gives time back rather than taking it.
Shrink the blast radius. 60879 needs a low-privileged account to work. That’s this Thursday’s post: five ways to audit your roles and permission lists before somebody else does.
ERP isn’t dying and PeopleSoft isn’t the problem. The customization layer and the staffing model are what’s out of date — and only one of those two is on your roadmap.
🌐 Join the Community
Subscribe to PeopleSoft Cloud for the Monday Digest and Thursday practitioner posts — no vendor spin, just what changed and what to do about it.
✅ Monday: what moved in the PeopleSoft, Oracle and ERP world, with a read on why it matters ✅ Thursday: five verifiable actions you can run this week, free, every week ✅ Written by a practitioner who still has to make the change window



