Azul Systems has announced it will deliver monthly Critical Security Patch Updates (CSPUs) for Java Long-Term Support (LTS) versions starting August 2026, covering both Azul Core and Azul Prime. The move marks a significant shift from the traditional quarterly update cadence, which the company says can leave enterprises exposed for weeks after a serious vulnerability is discovered.
Azul Shifts To Monthly Java Security Update Cadence
Azul’s CSPUs will be released on the third Tuesday of each month, but only when a high-priority fix is warranted; coverage spans all LTS versions Azul supports: Java 8, 11, 17, 21, and 25, as well as the current release, Java 26. Notably, it will also extend monthly CSPUs to Java 6 and 7, catering to organizations that still run these older versions in production environments.
The company’s approach builds on an existing model it has applied to quarterly updates. It currently ships two types of quarterly updates: Patch Set Updates (PSUs), which include the full set of quarterly changes, and Critical Patch Updates (CPUs), which deliver security fixes only on a stabilized code base. The new monthly CSPUs extend the CPU model to a monthly rhythm. Each update targets only identified vulnerabilities tracked as Common Vulnerabilities and Exposures (CVEs), without bundling unrelated changes that could introduce regressions into production systems.
Scott Sellers, co-founder and CEO, said AI is a factor in the policy change. “As AI sharply increases the volume of threats enterprises face, enterprises shouldn’t have to choose between the two. Monthly security-only updates are the new standard Azul is setting for how enterprises protect their Java estates.”
Pokdepinion: Moving from quarterly to monthly security patches sounds like progress until you realise the real story is that quarterly patches were always too slow and it took AI-accelerated exploitation to force the change.

