From Oracle Regarding Critical Patch Updates and Security Alert Notifications:
"Our customers should be encouraged to always keep their software current. To help facilitate this, customers can sign up to receive quarterly Critical Patch Updates and Security Alert notifications. The Critical Patch Update (CPU) is the primary mechanism for the release of all security bug fixes for all Oracle products. Critical Patch Updates are released quarterly on the Tuesday closest to the 17th of the month in January, April, July, and October. In addition, Oracle retains the ability to issue out of schedule patches or workaround instructions in case of particularly critical vulnerabilities and/or when active exploits are reported "in the wild." This program is known as the Security Alert program.