Update to RSA Authentication Manager Security Patching Process
a day ago

Date: July 2026

Product: RSA Authentication Manager (AM)

 

Overview

This advisory provides information regarding upcoming changes to the security patching and release process for RSA Authentication Manager (AM) in response to Oracle's transition from a quarterly Critical Patch Update (CPU) model to a monthly Critical Security Patch Update (CSPU) model.

This advisory is intended to inform customers of RSA's planned approach for evaluating, communicating, and delivering security updates related to Oracle components used within Authentication Manager.

 

Current Patching Cadence

The current security patching cadence for RSA Authentication Manager is as follows:

  • Security updates are delivered on an established quarterly release cadence.
  • This cadence aligns with Oracle's historical quarterly CPU schedule.
  • AM incorporates Oracle WebLogic and Java components, making Oracle security updates a key dependency.

Oracle Security Update Process Change

Oracle has announced a transition from its traditional quarterly Critical Patch Update cycle to a monthly Critical Security Patch Update (CSPU) model beginning from May 2026.

As AM utilizes Oracle WebLogic and Java technologies, RSA is adjusting its release strategy to ensure timely assessment and remediation of Oracle security vulnerabilities that may impact AM deployments.

 

Planned Authentication Manager Release Process

To align with Oracle's monthly security update cadence, RSA is implementing the following process:

 

1. Monthly Security Assessment and Customer Communication

For each Oracle monthly CSPU release, RSA will:

  • Evaluate all Oracle security fixes for potential impact to AM.
  • Determine whether vulnerabilities affect Oracle WebLogic components utilized within AM.
  • Publish a monthly advisory communicating
    - the impact assessment results,
    - whether customer action is required,
    - and availability of any AM security remediation.

2. Monthly Hotfix Releases (When Required)

If Oracle's monthly CSPU contains security fixes that materially impact AM, the following applies:

  • RSA may issue a hotfix release outside the standard quarterly schedule.
  • These hotfixes will focus on addressing affected Oracle components and related security exposure.
  • Release availability and deployment guidance will be communicated through the advisories and documentation published with the hotfix.

3. Continued Quarterly AM Releases

RSA will continue its established quarterly AM patch release cadence, which will include the following:

  • Product defect fixes
  • Enhancements and maintenance updates
  • Cumulative incorporation of applicable hotfixes released during the quarter

Customer Impact

At this time, the following applies:

  • No immediate customer action is required.
  • AM customers should expect periodic advisories following Oracle monthly CSPU releases.
  • Customers are encouraged to monitor RSA Security Advisories and release communications for future updates.

For additional information or support, please contact RSA Customer Support or your RSA account representative.

Announcement