Azul to move Java critical security patch updates from quarterly to monthly

0

Azul says it will begin delivering monthly Critical Security Patch Updates (CSPUs) for Java Long-Term Support (LTS) versions from August 2026, shifting away from the traditional quarterly cadence.

The company said the change is intended to reduce the time systems may remain exposed when a high-severity vulnerability is disclosed shortly after a scheduled quarterly release, leaving organisations waiting weeks for the next round of fixes.

Under the new schedule, Azul said CSPUs will be issued on the third Tuesday of each month “when a high-priority fix is warranted”. Updates will cover the LTS versions Azul supports: Java 8, 11, 17, 21 and 25, as well as the current release, Java 26. The company also said it will provide monthly CSPUs for Java 6 and 7 versions it supports, aimed at organisations still running those releases in production.

Azul framed the move as a response to a faster-moving vulnerability environment, arguing that AI is accelerating the discovery and exploitation of software flaws and increasing the volume of issues requiring remediation.

The company said it plans to maintain a security-only approach designed to limit regression risk. Azul described its existing quarterly model as offering Patch Set Updates (PSUs) containing the full set of changes, alongside Critical Patch Updates (CPUs) that focus on security fixes. It said CSPUs extend the security-only model to a monthly cadence, targeting Common Vulnerabilities and Exposures (CVEs) without bundling unrelated changes.

Azul co-founder and CEO Scott Sellers said: “As AI sharply increases the volume of threats enterprises face, enterprises shouldn’t have to choose between the two. Monthly security-only updates are the new standard Azul is setting for how enterprises protect their Java estates.”

Azul said it will continue working with the OpenJDK community and the OpenJDK Vulnerability Group on Java security.

Share.