Scott-Sellers President, CEO & Co-Founder Azul
Starting in August 2026, Azul will shift from quarterly to monthly critical security updates for all supported Java LTS versions, according to the company, covering releases from Java 6 through Java 26.

Azul is changing how it releases security updates for Java: starting in August 2026, the company plans to publish critical security patches (Critical Security Patch Updates, CSPUs) for all supported Java Long-Term Support versions on a monthly basis instead of the current quarterly cycle. According to the company, the change applies to both the Azul Core and Azul Prime product lines.

Azul justifies the move by pointing to the current threat environment, which it says the previous three-month cadence can no longer adequately cover. If a serious vulnerability emerges shortly after a scheduled update, it can remain unpatched for weeks until the next regular fix is released. Moving to a monthly cycle is intended to shorten that window without compromising the production-grade stability enterprises require.

As context for the change, Azul cites the influence of artificial intelligence on the security landscape. AI systems, the company says, are being used by defenders and attackers alike to identify and exploit vulnerabilities more quickly, while the overall number of vulnerabilities requiring fixes continues to grow. Against that backdrop, Azul argues that waiting up to 90 days for the next quarterly update is increasingly difficult to justify.

Going forward, CSPUs are to be published on the third Tuesday of each month whenever a priority fix is required. According to Azul, this gives enterprises a predictable security cadence instead of having to wait for the next quarterly release. The monthly patches are intended to cover all currently supported LTS versions, specifically Java 8, 11, 17, 21 and 25, as well as the current release, Java 26. Azul says it will also apply the monthly cadence to the older versions Java 6 and 7, which it supports separately, so that organizations still running legacy Java installations in production are meant to benefit as well.

In terms of content, Azul is building on a model already used for its previous quarterly updates. Alongside comprehensive Patch Set Updates (PSUs), which bundle all changes from a given quarter and typically comprise several hundred individual changes, Azul separately publishes Critical Patch Updates (CPUs). These are built on a stabilized, production-tested code base and contain only security-related fixes. The new CSPUs apply this CPU approach — following what the company calls a “stability-first” principle — on a monthly cadence: they are meant to deliver targeted fixes for known vulnerabilities catalogued as CVEs (Common Vulnerabilities and Exposures), without additional functional changes that could increase the risk of regressions. Azul says it will continue to work closely with the OpenJDK community and the OpenJDK Vulnerability Group.

Scott Sellers, co-founder and CEO of Azul, is quoted in the announcement as saying that as AI increases the volume of threats organizations face, they should not have to choose between security and stability. He describes monthly, security-only updates as the new standard Azul is setting for protecting enterprise Java environments.

For enterprises running production Java environments, the shift mainly means a tighter patch-planning cadence: instead of quarterly maintenance windows, IT teams will need to check monthly whether a CSPU is available and needs to be applied. Because the updates are said to contain only security-relevant changes and build on the same stabilized code base as the previous CPUs, the additional testing burden is expected to remain limited. Whether the monthly cadence holds up in practice will likely depend on how reliably Azul meets its announced release date over an extended period.

According to the company, Azul supports business-critical systems for 36 percent of Fortune 100 companies, half of the ten highest-value Forbes brands by brand value, and ten of the world’s leading financial trading firms. Further information on Azul’s Java support and the new patch schedule is available on the company’s website. For enterprise IT teams, the shift mainly means a tighter cadence for patch planning and testing.

By Jakob Jung

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM. Contact via Mail: jakob.jung@security-storage-und-channel-germany.de

Leave a Reply

Your email address will not be published. Required fields are marked *

WordPress Cookie Notice by Real Cookie Banner