Home
News
Tech Grid
Interviews
Anecdotes
Think Stack
Press Releases
Articles
  • Home
  • /
  • News
  • /
  • AI
  • /
  • Enterprise AI
  • /
  • Azul to Deliver Monthly Critical Security Patch Updates for Java Across All Supported LTS Versions
  • Enterprise AI

Azul to Deliver Monthly Critical Security Patch Updates for Java Across All Supported LTS Versions


Azul to Deliver Monthly Critical Security Patch Updates for Java Across All Supported LTS Versions
  • by: Business Wire
  • |
  • July 24, 2026

Azul, the trusted leader in enterprise Java for today's AI and cloud-first world, has announced that it will deliver monthly Critical Security Patch Updates (CSPUs) for Java Long-Term Support (LTS) versions for both Azul Core and Azul Prime, starting in August 2026. The traditional quarterly update cadence can no longer keep pace, as a serious vulnerability surfacing just after a scheduled update can sit unpatched for weeks before the next fix ships. Azul is moving to a monthly rhythm to close that exposure window, delivered with the production-grade stability enterprises depend on.

Quick Intel

  • Azul will deliver monthly Critical Security Patch Updates (CSPUs) starting August 18, 2026, on the third Tuesday of each month when high-priority fixes are needed .

  • CSPUs will cover all supported LTS versions: Java 8, 11, 17, 21, and 25, as well as the current release (Java 26) .

  • Azul will also extend monthly CSPUs to Java 6 and 7 versions it supports, targeting organizations still running older Java in production .

  • CSPUs are security-only updates, carrying fixes for tracked CVEs without bundling unrelated changes that raise regression risk .

  • The shift responds to AI-accelerated vulnerability discovery and exploitation, making the 90-day quarterly wait increasingly untenable .

  • Azul will continue working within the OpenJDK community and the OpenJDK Vulnerability Group to advance Java security .

Azul to Deliver Monthly Critical Security Patch Updates for Java Across All Supported LTS Versions

Azul, the trusted leader in enterprise Java for today's AI and cloud-first world, today announced that it will deliver monthly Critical Security Patch Updates (CSPUs) for Java Long-Term Support (LTS) versions for both Azul Core and Azul Prime, starting in August 2026. The traditional quarterly update cadence can no longer keep pace, as a serious vulnerability surfacing just after a scheduled update can sit unpatched for weeks before the next fix ships. Azul is moving to a monthly rhythm to close that exposure window, delivered with the production-grade stability enterprises depend on .

Why Monthly, and Why Now

The shift reflects a broad change in the security landscape: AI now accelerates how quickly vulnerabilities are discovered and exploited — by defenders and attackers alike — and the volume of issues that must be addressed is rising. In that environment, waiting up to 90 days for the next quarterly update is increasingly untenable .

A Predictable Monthly Schedule

Azul's CSPUs will be released monthly, on the third Tuesday of each month, when a high-priority fix is warranted, giving organizations a predictable, plannable security cadence rather than waiting for the next quarterly update. Azul will provide CSPUs across all the LTS versions it supports — Java 8, 11, 17, 21 and 25 — as well as the current release (Java 26). Azul will also deliver CSPUs for the Java 6 and 7 versions it supports, extending the same monthly security cadence to organizations still running older Java versions in production .

The Same Stability-First Model

Azul brings a proven model to this faster cadence. For years, it has delivered Java updates in two forms each quarter: Patch Set Updates (PSUs), which carry the full set of quarterly changes (typically measured in the hundreds), and Critical Patch Updates (CPUs), which deliver security fixes only, built on a stabilized, production-proven code base. Azul's CSPUs extend that same security-only, stability-first CPU model to a monthly rhythm — targeted fixes for identified vulnerabilities tracked as Common Vulnerabilities and Exposures (CVEs), without the unrelated changes that raise regression risk. Azul will continue to work within the OpenJDK community and the OpenJDK Vulnerability Group to advance Java security .

Executive Perspective

"For years, the world's most demanding enterprises have trusted Azul to deliver security and stability together, and on time," said Scott Sellers, co-founder and CEO of Azul. "As AI sharply increases the volume of threats enterprises face, enterprises shouldn't have to choose between the two. Monthly security-only updates are the new standard Azul is setting for how enterprises protect their Java estates" .

Managing the Faster Cadence

Azul's release infrastructure and validation processes are built to support the monthly cadence without adding operational burden for customers. Because CSPUs are scoped specifically to vulnerability fixes and undergo rigorous stability validation before release, enterprises can apply critical patches with confidence across mission-critical systems without expanding their internal testing cycles .

About Azul

Azul is the trusted leader in enterprise Java for today's AI and cloud-first world. Its open source-based Java platform empowers organizations to optimize the entire Java lifecycle to accelerate performance, strengthen security, reduce licensing and cloud costs, and boost developer productivity. Azul powers mission-critical systems for 36% of the Fortune 100, 50% of the Forbes Top 10 World's Most Valuable Brands and the world's top 10 financial trading companies .

  • Security UpdateEnterprise JavaAI
News Disclaimer
  • Share