Date: July 2026
Product: RSA Authentication Manager (AM)
Overview
This advisory provides information regarding upcoming changes to the security patching and release process for RSA Authentication Manager (AM) in response to Oracle's transition from a quarterly Critical Patch Update (CPU) model to a monthly Critical Security Patch Update (CSPU) model.
This advisory is intended to inform customers of RSA's planned approach for evaluating, communicating, and delivering security updates related to Oracle components used within Authentication Manager.
Current Patching Cadence
The current security patching cadence for RSA Authentication Manager is as follows:
- Security updates are delivered on an established quarterly release cadence.
- This cadence aligns with Oracle's historical quarterly CPU schedule.
- AM incorporates Oracle WebLogic and Java components, making Oracle security updates a key dependency.
Oracle Security Update Process Change
Oracle has announced a transition from its traditional quarterly Critical Patch Update cycle to a monthly Critical Security Patch Update (CSPU) model beginning from May 2026.
As AM utilizes Oracle WebLogic and Java technologies, RSA is adjusting its release strategy to ensure timely assessment and remediation of Oracle security vulnerabilities that may impact AM deployments.
Planned Authentication Manager Release Process
To align with Oracle's monthly security update cadence, RSA is implementing the following process:
1. Monthly Security Assessment and Customer Communication
For each Oracle monthly CSPU release, RSA will:
- Evaluate all Oracle security fixes for potential impact to AM.
- Determine whether vulnerabilities affect Oracle WebLogic components utilized within AM.
- Publish a monthly advisory communicating
- the impact assessment results,
- whether customer action is required,
- and availability of any AM security remediation.
2. Monthly Hotfix Releases (When Required)
If Oracle's monthly CSPU contains security fixes that materially impact AM, the following applies:
- RSA may issue a hotfix release outside the standard quarterly schedule.
- These hotfixes will focus on addressing affected Oracle components and related security exposure.
- Release availability and deployment guidance will be communicated through the advisories and documentation published with the hotfix.
3. Continued Quarterly AM Releases
RSA will continue its established quarterly AM patch release cadence, which will include the following:
- Product defect fixes
- Enhancements and maintenance updates
- Cumulative incorporation of applicable hotfixes released during the quarter
Customer Impact
At this time, the following applies:
- No immediate customer action is required.
- AM customers should expect periodic advisories following Oracle monthly CSPU releases.
- Customers are encouraged to monitor RSA Security Advisories and release communications for future updates.
For additional information or support, please contact RSA Customer Support or your RSA account representative.
Related Articles
RSA MFA Agent 9.0 for PAM - Installation and Configuration Guide for Oracle and RHEL (German) 14Number of Views How to close Open Violations for inactive Segregation of Duties (SoD) and User Access Rules in RSA Identity Governance & L… 83Number of Views RSA-2026-11: RSA Authentication Manager Security Update for Third-Party Component Vulnerabilities 15Number of Views Authentication Manager Security Console and Operations Console Inaccessible After Certificate Update 2.54KNumber of Views RSA Announces RSA Authentication Manager 8.9 Patch 2 Hotfix 1 and Updated Web-Tier Server 17Number of Views
Trending Articles
RSA Announces the Release of RSA MFA Agent 2.5 for Microsoft Windows RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device How to generate a PASSCODE for manual entry on a Ericsson R380 WAP phone