Oracle’s Critical Patch Update is out for July 2015:
Affected are database versions 188.8.131.52, 184.108.40.206, 220.127.116.11, 18.104.22.168 and 22.214.171.124.
This is the final patch for both the 126.96.36.199 and 188.8.131.52 releases. The final patch for 184.108.40.206 will be released in January 2016.
The most prominent bug on the risk matrix is CVE-2015-2629 whereby a remote authenticated user can exploit a flaw in the Java VM component to gain elevated privileges.
For the 220.127.116.11 patches, you can apply one of the following:
18.104.22.168 SPU for UNIX: patch 20803583
22.214.171.124.7 PSU for UNIX: patch 20760982
126.96.36.199.17 Quarterly Database Patch for Exadata (July 2015): patch 21142006
July 2015 Quarterly Full-Stack Patch for Exadata: patch 21186703
Don’t forget your Grid Infrastructure patching:
188.8.131.52 PSU for UNIX: patch 20996923
And, of course, ever since those Java bugs were discovered, we should also patch the JVM:
184.108.40.206.4 Database PSU for UNIX: patch 21068539