02. June 2026
Statement on the Oracle Critical Patch Update (April 2026) – Oracle APEX
We would like to inform you about the release of Oracle's regular security patch package (Critical Patch Update Advisory – April 2026). Our goal is to provide you with a quick summary of the impact on your Oracle APEX ver. 24.2 environment.

According to Oracle's official statement (article available here), the following applies to the Oracle APEX component:
- No critical vulnerabilities in the APEX code: The current report confirms that no new vulnerabilities were found directly in the Oracle APEX platform's own code that could be exploited by attackers.
- Third-party library updates: The patch includes updates for external libraries (specifically DOMPurify and turndown). Flaws were identified in these libraries (CVE-2026-0540 and CVE-2025-9670); however, Oracle lists their status as "non-exploitable."
- Low security risk: The analysis confirms that the vulnerable code in these libraries is not active within the Oracle APEX execution path (vulnerable_code_not_in_execute_path). This means that even though the flaws are listed in the report, they do not pose a real risk to your data or applications in this environment.
Our recommendation and next steps
Based on the facts above and confirmation that the reported CVEs are not exploitable within the Oracle APEX architecture, we have assessed the risk as minimal.
Should you have any questions, I remain fully at your disposal.





