SecurityBrief Canada - Technology news for CISOs & cybersecurity decision-makers
Canada
Azul to launch monthly Java security patch updates

Azul to launch monthly Java security patch updates

Thu, 23rd Jul 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Azul will introduce monthly Critical Security Patch Updates for supported Java Long-Term Support versions across Azul Core and Azul Prime, starting in August 2026.

The change is intended to reduce the time serious vulnerabilities can remain unpatched under the traditional quarterly release cycle.

Under the plan, Azul will issue security updates on the third Tuesday of each month when a high-priority fix is needed. The programme will cover supported LTS releases including Java 8, 11, 17, 21 and 25, as well as the current release, Java 26.

It will also extend the same monthly patch schedule to supported Java 6 and 7 versions, aimed at organisations that still run older releases in production.

Security cadence

The existing quarterly update model leaves a gap when serious flaws emerge shortly after a scheduled release, as users may then wait weeks for the next official fix. Azul linked the faster timetable to a broader shift in the threat landscape, arguing that artificial intelligence is increasing the speed at which vulnerabilities are identified and exploited.

The shift adds a monthly layer to a model Azul already uses for its quarterly releases. Those releases currently come in two forms: Patch Set Updates, which include the full range of quarterly changes, and Critical Patch Updates, which contain security fixes only and are based on a stabilised code base.

Monthly CSPUs will follow that security-only approach. The updates will target identified vulnerabilities tracked as Common Vulnerabilities and Exposures, while avoiding unrelated code changes that can increase the risk of regressions in production systems.

Azul said it would continue to work within the OpenJDK community and the OpenJDK Vulnerability Group on Java security matters.

Wider pressure

The announcement reflects a broader tension for companies running large Java estates in production. Security teams are under pressure to apply fixes more quickly, while engineering teams try to avoid disruptions caused by frequent or wide-ranging software changes.

By keeping the monthly releases focused on security issues rather than feature or platform changes, Azul aims to make a faster patching cycle easier for customers with established testing and deployment processes to plan around.

Its release and validation processes are designed to support that model, with testing intended to reduce the likelihood that urgent security updates introduce application problems or operational disruption.

Azul positions the offering around supported LTS versions, which many large organisations keep in service for extended periods. Extending coverage to Java 6 and 7 broadens the relevance of the move for businesses maintaining older applications that are difficult or costly to migrate.

That may be particularly important in sectors where legacy Java systems remain embedded in core operations, including financial services and other industries with large, long-lived software estates.

Scott Sellers, Co-Founder and Chief Executive Officer at Azul, outlined the company's view of the new update cycle. "For years, the world's most demanding enterprises have trusted Azul to deliver security and stability together, and on time," he said.

He added: "As AI sharply increases the volume of threats enterprises face, enterprises shouldn't have to choose between the two. Monthly security-only updates are the new standard Azul is setting for how enterprises protect their Java estates."