Press ReleaseThreat Detection & Defense

Azul to Deliver Monthly Critical Security Patch Updates for Java Across All Supported LTS Versions

Monthly Security-Only, Stability-First Cadence Delivers Speed Without the Regression Risk

Azul, the trusted leader in enterprise Java for today’s AI and cloud-first world, today announced that it will deliver monthly Critical Security Patch Updates (CSPUs) for Java Long-Term Support (LTS) versions for both Azul Core and Azul Prime, starting in August 2026. The traditional quarterly update cadence can no longer keep pace, as a serious vulnerability surfacing just after a scheduled update can sit unpatched for weeks before the next fix ships. Azul is moving to a monthly rhythm to close that exposure window, delivered with the production-grade stability enterprises depend on.

Why Monthly, and Why Now

The shift reflects a broad change in the security landscape: AI now accelerates how quickly vulnerabilities are discovered and exploited—by defenders and attackers alike—and the volume of issues that must be addressed is rising. In that environment, waiting up to 90 days for the next quarterly update is increasingly untenable.

A Predictable Monthly Schedule

Azul’s CSPUs will be released monthly, on the third Tuesday of each month, when a high-priority fix is warranted, giving organisations a predictable, plannable security cadence rather than requiring them to wait for the next quarterly update. Azul will provide CSPUs across all the LTS versions it supports—Java 8, 11, 17, 21, and 25—as well as the current release (Java 26). Azul will also deliver CSPUs for the Java 6 and 7 versions it supports, extending the same monthly security cadence to organisations still running older Java versions in production.

The Same Stability-First Model

Azul brings a proven model to this faster cadence. For years, it has delivered Java updates in two forms each quarter: Patch Set Updates (PSUs), which carry the full set of quarterly changes (typically measured in the hundreds), and Critical Patch Updates (CPUs), which deliver security fixes only, built on a stabilised, production-proven code base. Azul’s CSPUs extend that same security-only, stability-first CPU model to a monthly rhythm—targeted fixes for identified vulnerabilities tracked as Common Vulnerabilities and Exposures (CVEs), without the unrelated changes that raise regression risk. Azul will continue to work within the OpenJDK community and the OpenJDK Vulnerability Group to advance Java security.

“For years, the world’s most demanding enterprises have trusted Azul to deliver security and stability together, and on time,” said Scott Sellers, co-founder and CEO of Azul. “As AI sharply increases the volume of threats enterprises face, enterprises shouldn’t have to choose between the two. Monthly security-only updates are the new standard Azul is setting for how enterprises protect their Java estates.”

CSA Editorial

Launched in Jan 2018, in partnership with Cyber Security Malaysia (an agency under MOSTI). CSA is a news and content platform focusing on key issues in cybersecurity in the region. CSA is targeted to serve the needs of cybersecurity professionals, IT professionals, Risk professionals and C-Levels who have an obligation to understand the impact of cyber threats.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *