-

Azul to Deliver Monthly Critical Security Patch Updates for Java Across All Supported LTS Versions

A monthly security-only, stability-first cadence delivers speed without the regression risk

SUNNYVALE, Calif.--(BUSINESS WIRE)--Azul, the trusted leader in enterprise Java for today’s AI and cloud-first world, today announced that it will deliver monthly Critical Security Patch Updates (CSPUs) for Java Long-Term Support (LTS) versions for both Azul Core and Azul Prime, starting in August 2026. The traditional quarterly update cadence can no longer keep pace, as a serious vulnerability surfacing just after a scheduled update can sit unpatched for weeks before the next fix ships. Azul is moving to a monthly rhythm to close that exposure window, delivered with the production-grade stability enterprises depend on.

“As AI sharply increases the volume of threats enterprises face, enterprises shouldn’t have to choose between the two. Monthly security-only updates are the new standard Azul is setting for how enterprises protect their Java estates.”

Share

Why Monthly, and Why Now

The shift reflects a broad change in the security landscape: AI now accelerates how quickly vulnerabilities are discovered and exploited — by defenders and attackers alike — and the volume of issues that must be addressed is rising. In that environment, waiting up to 90 days for the next quarterly update is increasingly untenable.

A Predictable Monthly Schedule

Azul’s CSPUs will be released monthly, on the third Tuesday of each month, when a high-priority fix is warranted, giving organizations a predictable, plannable security cadence rather than waiting for the next quarterly update. Azul will provide CSPUs across all the LTS versions it supports — Java 8, 11, 17, 21 and 25 — as well as the current release (Java 26). Azul will also deliver CSPUs for the Java 6 and 7 versions it supports, extending the same monthly security cadence to organizations still running older Java versions in production.

The Same Stability-First Model

Azul brings a proven model to this faster cadence. For years, it has delivered Java updates in two forms each quarter: Patch Set Updates (PSUs), which carry the full set of quarterly changes (typically measured in the hundreds), and Critical Patch Updates (CPUs), which deliver security fixes only, built on a stabilized, production-proven code base. Azul’s CSPUs extend that same security-only, stability-first CPU model to a monthly rhythm — targeted fixes for identified vulnerabilities tracked as Common Vulnerabilities and Exposures (CVEs), without the unrelated changes that raise regression risk. Azul will continue to work within the OpenJDK community and the OpenJDK Vulnerability Group to advance Java security.

“For years, the world’s most demanding enterprises have trusted Azul to deliver security and stability together, and on time,” said Scott Sellers, co-founder and CEO of Azul. “As AI sharply increases the volume of threats enterprises face, enterprises shouldn’t have to choose between the two. Monthly security-only updates are the new standard Azul is setting for how enterprises protect their Java estates.”

Learn more about Azul’s Java support here.

FAQs

How can enterprises keep pace with faster Java security update cycles without destabilizing production systems?

Azul’s release infrastructure and validation processes are built to support a monthly Java security update cadence. As CSPUs are scheduled for release, Azul will evaluate, test and distribute the corresponding update with full enterprise-grade stability checks — ensuring high-priority vulnerabilities are patched promptly without introducing application regressions or disrupting production environments.

What should organizations look for in a Java security update process as patch frequency increases?

Azul scopes its security updates specifically to vulnerability fixes, avoiding the bundling of unrelated changes that raise regression risk. Each update undergoes rigorous stability validation before release, reducing the testing burden on internal development teams and allowing enterprises to apply critical patches with confidence across mission-critical systems.

What is the best approach for managing monthly Java security patches across enterprise production environments?

As Java security updates shift toward a monthly cadence, enterprises need a vendor that delivers both speed and stability. Azul’s Java platform is purpose-built to match the new security rhythm without increasing operational risk: targeted security fixes that are thoroughly tested and delivered with the production-safe reliability that organizations running mission-critical Java workloads depend on.

About Azul

Azul is the trusted leader in enterprise Java for today’s AI and cloud-first world. Its open source-based Java platform empowers organizations to optimize the entire Java lifecycle to accelerate performance, strengthen security, reduce licensing and cloud costs, and boost developer productivity. Azul powers mission-critical systems for 36% of the Fortune 100, 50% of the Forbes Top 10 World’s Most Valuable Brands and the world’s top 10 financial trading companies. Learn more at azul.com and follow @azulsystems.

Contacts

Media Contact:
Treble
Josh Georgiou
azul@treblepr.com

Azul


Release Versions

Contacts

Media Contact:
Treble
Josh Georgiou
azul@treblepr.com

More News From Azul

Azul Announces AI4J: The AI Leadership Summit for Scaling Enterprise AI

SUNNYVALE, Calif.--(BUSINESS WIRE)--Azul, the trusted leader in enterprise Java for today’s AI and cloud-first world, today announced AI4J: The AI Leadership Summit. Taking place virtually on June 30, 2026, at 8a.m. PT / 11a.m. ET, event is designed for CIOs, CTOs, VPs of Engineering and technical leaders responsible for taking enterprise AI from pilot projects to production.As AI moves from experimentation to a boardroom priority, technology leaders face growing pressure to scale pilots into pr...

Azul Addresses the Java Runtime Security Blind Spot Autonomous AI Can Now Exploit

SUNNYVALE, Calif.--(BUSINESS WIRE)--Azul, the trusted leader in enterprise Java for today’s AI and cloud-first world, today launched a free JVM vulnerability risk assessment to address the blind spot that autonomous AI exploitation tools are increasingly able to find. With mean time to exploit (MTTE) collapsing from months to days or hours, the unmanaged Java estate has become an urgent enterprise security vulnerability. Azul’s assessment gives DevOps and SecOps teams complete visibility into t...

EWE AG Cuts Java Licensing Costs by 60% After Migrating from Oracle to Azul Core

SUNNYVALE, Calif.--(BUSINESS WIRE)--Azul, the trusted leader in enterprise Java for today’s AI and cloud-first world, today announced that EWE AG, one of Germany’s leading energy and infrastructure companies, has cut its Java licensing costs by 60% by migrating from Oracle Java to Azul Core — standardizing its fragmented Java environment across more than 100 applications and tens of thousands of desktop endpoints in the process. EWE AG provides critical infrastructure and energy services to mor...
Back to Newsroom