Database

Oracle Enterprise Manager 24ai - Perl, WLS and OWSM: The Hidden Agent Patches of August 2026 CSPU

Keep your Agents up-to-date - NOW!

The August 2026 Critical Security Patch Update (CSPU) for Oracle Enterprise Manager 24ai introduces additional mandatory patches for the monitoring agent beyond the standard Release Update. Unlike the RU, which can be deployed via EM patch plans, two of the five required patches are Middleware components that must be applied manually via opatch directly on each target server. Oracle’s recommended approach for keeping the agent fleet consistent is the use of Agent Gold Images after completing the patch cycle.

My Oracle Support Note CPU329 - Critical Security Patch Update (CSPU) Program August 2026 Patch Availability Document (EM-only)

Section 3.1.4 list the patches and fixes for the monitoring agents recommended to apply. There are five patches liste for product Base Platform Agent home. Source: oracle.com.

Product HomePatchesAdvisory NumberComments
Base Platform Agent homeOracle Enterprise Manager 24ai Release 1 Update 12 (24.1.0.12) for Oracle Management Agent PATCH 39675970 or laterCVE-2026-2332, CVE-2026-60822, CVE-2026-61300, CVE-2026-70737, CVE-2026-70684
Base Platform Agent homeOPatch 13.9.4.2.24 PATCH 28186730 or laterReleased July 2026
Base Platform Agent homePerl 5.40.2 Patch for EM 24.1 PATCH 38445807 or laterReleased April 2026. On IBM AIX 64 bit Platform only, apply PATCH 39446675 instead of PATCH 38445807. After applying the patch, permissions of Perl may need to be updated. Refer to the Readme and KB885045 for details.
Base Platform Agent homeWLS PATCH SET UPDATE 12.2.1.4.260728 PATCH 39796340 or laterReleased August 2026
Base Platform Agent homeOWSM BUNDLE PATCH 12.2.1.4.260707 PATCH 39697343 or laterReleased August 2026

Documents

The Setup

  • Oracle Enterprise Manager 24ai Release Update 12 / Holistic applied / Standalone
  • Oracle Linux Server Release 9.x
  • Database Host Agent Relase Update 12 already applied by EM24ai patch plan function, no other patches applied
  • Database Host patch stage directory is /u01/app/oracle/stage - patch files transferred
  • All patch jobs on target host executed as OS user oracle.
  • Agent ORACLE_HOME is /u01/app/oracle/agent/agent_24.1.0.0.0.

Read the patch readme first and ensure, you download the patches according to your platform (Windows, ARM etc.).

Step 0 - Current State

The agent release update 12 is applied by EM patch plan, no current Perl or Middleware patches applied.

$ $ORACLE_HOME/OPatch/opatch lspatches

39676047;Oracle Enterprise Manager for Fusion Middleware 24ai Release 1 Plug-in Update 12 (24.1.1.12) for Oracle Management Agent (Discovery)
39676023;Oracle Enterprise Manager for Exadata 24ai Release 1 Plug-in Update 12 (24.1.1.12) for Oracle Management Agent (Discovery)
39676003;Oracle Enterprise Manager for Oracle Database 24ai Release 1 Plug-in Update 12 (24.1.1.12) for Oracle Management Agent (Discovery)
39675995;Oracle Enterprise Manager for Oracle Database 24ai Release 1 Plug-in Update 12 (24.1.1.12) for Oracle Management Agent
39675985;Oracle Enterprise Manager 24ai Release 1 Platform Update 12 (24.1.0.12) for Oracle Management Agent
37121017;Non System patch Tracking bug to repackage 19.24 version of UCP patch as 24.1 EM Agent patch
37121014;Non System patch Tracking bug to repackage 19.24 version of JDBC patch as 24.1 EM Agent patch
37096063;OSS 19C BUNDLE PATCH 12.2.1.4.241001
37087476;WLS PATCH SET UPDATE 12.2.1.4.240922

Step 1 - WLS PATCH SET UPDATE 12.2.1.4.260728 PATCH 39796340

Login into target host, extract the patch file and change directory.

$ cd /u01/app/oracle/stage
$ unzip p39796340_122140_Generic.zip
$ cd 39796340

Set ORACLE_HOME according your installation.

$ export ORACLE_HOME=/u01/app/oracle/agent/agent_24.1.0.0.0

Apply patch - output is redacted for better readability.

$ $ORACLE_HOME/OPatch/opatch apply

Output

Oracle Interim Patch Installer version 13.9.4.2.17
Copyright (c) 2026, Oracle Corporation.  All rights reserved.


Oracle Home       : /u01/app/oracle/agent/agent_24.1.0.0.0
Central Inventory : /u01/app/oraInventory
   from           : /u01/app/oracle/agent/agent_24.1.0.0.0/oraInst.loc
OPatch version    : 13.9.4.2.17
OUI version       : 13.9.4.0.0
Log file location : /u01/app/oracle/agent/agent_24.1.0.0.0/cfgtoollogs/opatch/opatch2026-08-21_09-29-44AM_1.log


OPatch detects the Middleware Home as "/u01/app/oracle/agent"

Verifying environment and performing prerequisite checks...
OPatch continues with these patches:   39796340  

Do you want to proceed? [y|n]
y
User Responded with: Y
All checks passed.

Please shutdown Oracle instances running out of this ORACLE_HOME on the local system.
(Oracle Home = '/u01/app/oracle/agent/agent_24.1.0.0.0')


Is the local system ready for patching? [y|n]
y
User Responded with: Y
Backing up files...
Applying interim patch '39796340' to OH '/u01/app/oracle/agent/agent_24.1.0.0.0'
ApplySession: Optional component(s) [ oracle.standalone.toplink, 12.2.1.4.0 ] , [ oracle.wls.rcu, 12.2.1.4.0 ] , [ oracle.wls.rcu, 12.2.1.4.0 ] , [ oracle.wls.rcu, 12.2.1.4.0 ] , [ oracle.wls.admin.console.en, 12.2.1.4.0 ] , [ oracle.wls.admin.console.en, 12.2.1.4.0 ] , [ oracle.fmwconfig.common.config.shared, 12.2.1.4.0 ] , [ oracle.org.apache.commons.commons.compress, 1.9.0.0.0 ] , [ oracle.org.apache.commons.commons.compress, 1.9.0.0.0 ] , [ oracle.wls.jrf.tenancy.common.sharedlib, 12.2.1.4.0 ] , [ oracle.wls.jrf.tenancy.common.sharedlib, 12.2.1.4.0 ] , [ oracle.wls.jrf.tenancy.common.sharedlib, 12.2.1.4.0 ] , [ oracle.wls.jrf.tenancy.ee.only.sharedlib, 12.2.1.4.0 ] , [ oracle.wls.jrf.tenancy.ee.only.sharedlib, 12.2.1.4.0 ] , [ oracle.com.fasterxml.jackson.jaxrs.jackson.jaxrs.json.provider, 2.9.9.0.0 ] , [ oracle.com.<REDACTED>
<REDACTED>
<REDACTED>
Patching component oracle.rsa.crypto, 12.2.1.4.0...

Patching component oracle.rsa.crypto, 12.2.1.4.0...

Patching component oracle.jse.dms, 12.2.1.4.0...

Patching component oracle.jse.dms, 12.2.1.4.0...

Patching component oracle.jrf.dms.common, 12.2.1.4.0...
Patch 39796340 successfully applied.
Sub-set patch [37087476] has become inactive due to the application of a super-set patch [39796340].
Please refer to Doc ID 2161861.1 for any possible further required actions.
Log file location: /u01/app/oracle/agent/agent_24.1.0.0.0/cfgtoollogs/opatch/opatch2026-08-21_09-29-44AM_1.log

OPatch succeeded.

Verification

By parameter lspatches, you can see patch 39796340 is listed on top.

$ $ORACLE_HOME/OPatch/opatch lspatches

39796340;WLS PATCH SET UPDATE 12.2.1.4.260728
39676047;Oracle Enterprise Manager for Fusion Middleware 24ai Release 1 Plug-in Update 12 (24.1.1.12) for Oracle Management Agent (Discovery)
39676023;Oracle Enterprise Manager for Exadata 24ai Release 1 Plug-in Update 12 (24.1.1.12) for Oracle Management Agent (Discovery)
39676003;Oracle Enterprise Manager for Oracle Database 24ai Release 1 Plug-in Update 12 (24.1.1.12) for Oracle Management Agent (Discovery)
39675995;Oracle Enterprise Manager for Oracle Database 24ai Release 1 Plug-in Update 12 (24.1.1.12) for Oracle Management Agent
39675985;Oracle Enterprise Manager 24ai Release 1 Platform Update 12 (24.1.0.12) for Oracle Management Agent
37121017;Non System patch Tracking bug to repackage 19.24 version of UCP patch as 24.1 EM Agent patch
37121014;Non System patch Tracking bug to repackage 19.24 version of JDBC patch as 24.1 EM Agent patch
37096063;OSS 19C BUNDLE PATCH 12.2.1.4.241001

Step 2 - Patch 39697343: OWSM BUNDLE PATCH 12.2.1.4.260707

Extract the patch file and change directory.

$ cd /u01/app/oracle/stage
$ unzip p39697343_122140_Generic.zip
$ cd 39697343

Set ORACLE_HOME according your installation if not already set or execute in another terminal.

$ export ORACLE_HOME=/u01/app/oracle/agent/agent_24.1.0.0.0

Apply patch.

$ $ORACLE_HOME/OPatch/opatch apply

Output

Oracle Interim Patch Installer version 13.9.4.2.17
Copyright (c) 2026, Oracle Corporation.  All rights reserved.


Oracle Home       : /u01/app/oracle/agent/agent_24.1.0.0.0
Central Inventory : /u01/app/oraInventory
   from           : /u01/app/oracle/agent/agent_24.1.0.0.0/oraInst.loc
OPatch version    : 13.9.4.2.17
OUI version       : 13.9.4.0.0
Log file location : /u01/app/oracle/agent/agent_24.1.0.0.0/cfgtoollogs/opatch/opatch2026-08-21_09-32-41AM_1.log


OPatch detects the Middleware Home as "/u01/app/oracle/agent"

Verifying environment and performing prerequisite checks...
OPatch continues with these patches:   39697343  

Do you want to proceed? [y|n]
y
User Responded with: Y
All checks passed.

Please shutdown Oracle instances running out of this ORACLE_HOME on the local system.
(Oracle Home = '/u01/app/oracle/agent/agent_24.1.0.0.0')


Is the local system ready for patching? [y|n]
y
User Responded with: Y
Backing up files...
Applying interim patch '39697343' to OH '/u01/app/oracle/agent/agent_24.1.0.0.0'
ApplySession: Optional component(s) [ oracle.wsm.console.core, 12.2.1.4.0 ] , [ oracle.wsm.pmlib, 12.2.1.4.0 ] , [ oracle.wsm.pmlib, 12.2.1.4.0 ] , [ oracle.wsm.jrf, 12.2.1.4.0 ] , [ oracle.wsm.jrf, 12.2.1.4.0 ] , [ oracle.wsm.agent.wls, 12.2.1.4.0 ]  not present in the Oracle Home or a higher version is found.

Patching component oracle.wsm.common, 12.2.1.4.0...

Patching component oracle.wsm.common, 12.2.1.4.0...

Patching component oracle.osdt.core, 12.2.1.4.0...
Patch 39697343 successfully applied.
Log file location: /u01/app/oracle/agent/agent_24.1.0.0.0/cfgtoollogs/opatch/opatch2026-08-21_09-32-41AM_1.log

OPatch succeeded.

Verification

By parameter lspatches, you can see patch 39697343 is listed on top.

$ $ORACLE_HOME/OPatch/opatch lspatches

39697343;OWSM BUNDLE PATCH 12.2.1.4.260707
39796340;WLS PATCH SET UPDATE 12.2.1.4.260728
39676047;Oracle Enterprise Manager for Fusion Middleware 24ai Release 1 Plug-in Update 12 (24.1.1.12) for Oracle Management Agent (Discovery)
39676023;Oracle Enterprise Manager for Exadata 24ai Release 1 Plug-in Update 12 (24.1.1.12) for Oracle Management Agent (Discovery)
39676003;Oracle Enterprise Manager for Oracle Database 24ai Release 1 Plug-in Update 12 (24.1.1.12) for Oracle Management Agent (Discovery)
39675995;Oracle Enterprise Manager for Oracle Database 24ai Release 1 Plug-in Update 12 (24.1.1.12) for Oracle Management Agent
39675985;Oracle Enterprise Manager 24ai Release 1 Platform Update 12 (24.1.0.12) for Oracle Management Agent
37121017;Non System patch Tracking bug to repackage 19.24 version of UCP patch as 24.1 EM Agent patch
37121014;Non System patch Tracking bug to repackage 19.24 version of JDBC patch as 24.1 EM Agent patch
37096063;OSS 19C BUNDLE PATCH 12.2.1.4.241001

Step 3 - Patch 38445807: PERL 5.40.2 PATCH FOR EM 24.1

Set ORACLE_HOME according your installation if not already set or execute in another terminal.

$ export ORACLE_HOME=/u01/app/oracle/agent/agent_24.1.0.0.0

Show the current agent Perl version on target server. In my case it’s 5.38.

$ $ORACLE_HOME/perl/bin/perl -version

This is perl 5, version 38, subversion 2 (v5.38.2) built for x86_64-linux-thread-multi
<REDACTED>

Extract the patch file and change directory.

$ cd /u01/app/oracle/stage
$ unzip p38445807_241000_Linux-x86-64.zip
$ cd 38445807

Stop the agent, verify it’s stopped properly.

$ $ORACLE_HOME/bin/emctl stop agent

Apply patch.

$ $ORACLE_HOME/OPatch/opatch apply

Output

Oracle Interim Patch Installer version 13.9.4.2.17
Copyright (c) 2026, Oracle Corporation.  All rights reserved.


Oracle Home       : /u01/app/oracle/agent/agent_24.1.0.0.0
Central Inventory : /u01/app/oraInventory
   from           : /u01/app/oracle/agent/agent_24.1.0.0.0/oraInst.loc
OPatch version    : 13.9.4.2.17
OUI version       : 13.9.4.0.0
Log file location : /u01/app/oracle/agent/agent_24.1.0.0.0/cfgtoollogs/opatch/opatch2026-08-21_09-49-55AM_1.log


OPatch detects the Middleware Home as "/u01/app/oracle/agent"

Verifying environment and performing prerequisite checks...
OPatch continues with these patches:   38445807  

Do you want to proceed? [y|n]
y
User Responded with: Y
All checks passed.
Backing up files...
Applying interim patch '38445807' to OH '/u01/app/oracle/agent/agent_24.1.0.0.0'

Patching component oracle.perlint, 5.38.2.0.0...
Patch 38445807 successfully applied.
Log file location: /u01/app/oracle/agent/agent_24.1.0.0.0/cfgtoollogs/opatch/opatch2026-08-21_09-49-55AM_1.log

OPatch succeeded.

Start the agent, verify it’s start properly and uploads data to Oracle Management Server.

$ $ORACLE_HOME/bin/emctl start agent
$ $ORACLE_HOME/bin/emctl status agent

Verification

By parameter lspatches, you can see patch 38445807 is listed on top.

$ $ORACLE_HOME/OPatch/opatch lspatches

38445807;PERL 5.40.2 patch for EM 24.1.0.0.0
39697343;OWSM BUNDLE PATCH 12.2.1.4.260707
39796340;WLS PATCH SET UPDATE 12.2.1.4.260728
39676047;Oracle Enterprise Manager for Fusion Middleware 24ai Release 1 Plug-in Update 12 (24.1.1.12) for Oracle Management Agent (Discovery)
39676023;Oracle Enterprise Manager for Exadata 24ai Release 1 Plug-in Update 12 (24.1.1.12) for Oracle Management Agent (Discovery)
39676003;Oracle Enterprise Manager for Oracle Database 24ai Release 1 Plug-in Update 12 (24.1.1.12) for Oracle Management Agent (Discovery)
39675995;Oracle Enterprise Manager for Oracle Database 24ai Release 1 Plug-in Update 12 (24.1.1.12) for Oracle Management Agent
39675985;Oracle Enterprise Manager 24ai Release 1 Platform Update 12 (24.1.0.12) for Oracle Management Agent
37121017;Non System patch Tracking bug to repackage 19.24 version of UCP patch as 24.1 EM Agent patch
37121014;Non System patch Tracking bug to repackage 19.24 version of JDBC patch as 24.1 EM Agent patch
37096063;OSS 19C BUNDLE PATCH 12.2.1.4.241001

Step 4 - Patch 28186730: OPATCH 13.9.4.2.24 FOR EM 13.5/24.1 AND FMW/WLS 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 AND IDM 14.1.2.1

Set ORACLE_HOME according your installation if not already set or execute in another terminal.

$ export ORACLE_HOME=/u01/app/oracle/agent/agent_24.1.0.0.0

Show the current OPatch version on target server. In my case it’s 13.9.4.2.17.

$ $ORACLE_HOMEOPatch/opatch version
OPatch Version: 13.9.4.2.17

OPatch succeeded.

Extract the patch file and change directory.

$ cd /u01/app/oracle/stage
$ unzip p28186730_1394224_Generic.zip
$ cd 6880880

Apply patch, this is NOT an OPatch command.

$ $ORACLE_HOME/oracle_common/jdk/bin/java -jar /u01/app/oracle/stage/6880880/opatch_generic.jar -silent oracle_home=$ORACLE_HOME

Output

Launcher log file is /tmp/OraInstall2026-08-21_10-12-43AM/launcher2026-08-21_10-12-43AM.log.
Extracting the installer . . . . Done
Checking if CPU speed is above 300 MHz.   Actual 2596.096 MHz    Passed
Checking swap space: must be greater than 512 MB.   Actual 6143 MB    Passed
Checking if this platform requires a 64-bit JVM.   Actual 64    Passed (-d64 flag is not required)
Checking temp space: must be greater than 300 MB.   Actual 13274 MB    Passed
Preparing to launch the Oracle Universal Installer from /tmp/OraInstall2026-08-21_10-12-43AM
Installation Summary


Disk Space : Required 49 MB, Available 146,578 MB
Feature Sets to Install:
        Next Generation Install Core 13.9.4.0.1
        OPatch 13.9.4.2.24
        OPatch Auto OPlan 13.9.4.2.24
Session log file is /tmp/OraInstall2026-08-21_10-12-43AM/install2026-08-21_10-12-43AM.log

Loading products list. Please wait.
 1%
 40%

Loading products. Please wait.
 42%
 44%
<REDACTED>
 98%
 99%

Updating Libraries

Starting Installations
 1%
 2%
 <REDACTED>
 46%
 47%
<REDACTED>
Saving the inventory glcm_encryption_lib

 Component : glcm_common_lib

Saving the inventory glcm_common_lib

The install operation completed successfully.

Logs successfully copied to /u01/app/oraInventory/logs.

Verification

By parameter version, you can see patch 28186730 is applied.

$ $ORACLE_HOME/OPatch/opatch version
OPatch Version: 13.9.4.2.24

OPatch succeeded.

Summary

The August 2026 CSPU brings five patches for the EM 24ai Agent home. Two of them - the WLS PSU and the OWSM Bundle Patch - are Middleware components that cannot be deployed through the standard EM patch plan workflow and must be applied manually via opatch on each target server. The Perl patch additionally requires a brief agent downtime. After completing all four opatch steps, upgrade OPatch itself using the Java-based installer to bring it to version 13.9.4.2.24.

Using Agent Gold Images is the recommended strategy to roll out the patched agent baseline consistently across your entire agent fleet - avoiding the need to repeat these manual steps on every individual host.

PATCH YOUR OEM AND YOUR AGENTS. Now. No excuses!