Oracle critical patch updates highlights growing patch fatigue

Oracle’s latest Critical Patch Update comes as many security teams continue to struggle with vulnerability fatigue and competing guidance on what to patch first.

Fortra’s Associate Director of Security Research and Development, Tyler Reguly had this to say:

It’s hard not to sound like a broken record these days when talking about security updates. We’re continually seeing large numbers of vulnerabilities and we’re all starting to feel a little burnt out. It’s really making it obvious that there are various camps within our industry that are at odds when it comes to how to address these issues. On one hand, you have the patch-everything crowd. Their polar opposite is the patch-minimally crowd that insists you should focus on only things that are exploited. Finally, you have the prioritize everything, but patch only what is critical. I’m sure there are people that sit at various points across that spectrum as well. 

On top of that, you have the security vendors, AI vendors, standards bodies, and governments dictating prioritization methods, patching speeds and more. What is a person to do? 

Step back and find your calm. I’ve said it before and I say it again, there is a light at the end of this tunnel and the record numbers of patches for record numbers of vulnerabilities will not last. I’m confident of this. Do everything you can to avoid burning out and just work on surviving this onslaught. 


My biggest problem with Oracle has always been the complexity of their installs and their patches. They are not a sysadmin’s best friend. When it comes to applications this complex, tooling is your friend. Whether that is vendor-provided tools or in-house applications, ensure that you can identify your assets, determine their patch level, and easily prioritize what needs to be patched first. If your tooling isn’t helping you achieve this, find new tooling. If you’re chopping wood and the axe just isn’t splitting the log, you don’t keep bashing it into the log hoping it will work. You get a wedge and a sledgehammer, or you sharpen the axe. The same thing is true with your security tools, if they aren’t working for you, fix them or replace them. 


I can’t help but wonder how many people truly understand where risk lies. I think that CISA BOD 26-04 did a great job of helping people to understand how to prioritize based on risk. I think that a 3-day turnaround is very tight when you need to also test your patches, but it helps lay out priorities that make a real difference – is it publicly exposed, is it on the Known Exploited Vulnerabilities list, can it be automated, and does it give complete control. When you can answer these questions, you can start to identify the risk that it plays. Are there other components you can include? Sure, but this is a great start if you don’t really know what risk looks like for your organization. Once you know what risk looks like, you can start to prioritize your patches more appropriately. 

Besides my usual advice of patch all the things, there needs to be a bit of a rethink about the patch regime that exists right now. Until that changes, patching all the things is the best advice that anyone has to go with.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading