Oracle September 2026 Critical Security Patch Update addresses 672 CVEs
Oracle's September 2026 CSPU fixes 672 CVEs across 673 patches, including 104 critical updates, with E-Business Suite receiving the most patches (159).
Oracle released its September 2026 Critical Security Patch Update fixing 672 unique CVEs via 673 security updates across 17 product families, with 104 patches (15.5%) rated critical and 503 rated high. Oracle E-Business Suite received the most patches at 159 (23.6%), followed by Fusion Middleware at 153, of which 78 are remotely exploitable without authentication. The CSPU is a monthly release cycle Oracle introduced in May 2026 between larger quarterly CPUs. Tenable will publish plugins to identify affected systems.
- 672 unique CVEs patched in 673 updates across 17 Oracle product families
- 104 patches (15.5%) rated critical; 503 rated high severity
- E-Business Suite led with 159 patches; Fusion Middleware had 78 remotely exploitable without auth
- CSPU is a monthly cycle introduced May 2026 between quarterly CPUs
Full article483 words · extracted from tenable.com · click to collapse
2-minute read Sep 15 2026
Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates.
Key Takeaways
- The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates
- 104 issues (15.5% of all patches) were assigned a critical severity rating
- Oracle E-Business Suite received the highest number of patches at 159, accounting for 23.6% of all patches
Background
On September 15, Oracle released its Critical Security Patch Update (CSPU) for September 2026. Beginning in May 2026, Oracle introduced CSPUs as a monthly release cycle that sits between the larger quarterly Critical Patch Updates (CPUs), addressing a focused set of high-severity issues on a faster cadence. This CSPU contains fixes for 672 unique CVEs in 673 security updates across 17 Oracle product families. Out of the 673 security updates published, 15.5% of patches were assigned a critical severity. High severity patches accounted for the bulk of security patches at 74.7%, followed by critical severity patches at 15.5%.

This month's update includes 104 critical patches across 104 CVEs.
| Severity | Issues Patched | CVEs |
|---|---|---|
| Critical | 104 | 104 |
| High | 503 | 503 |
| Medium | 59 | 58 |
| Low | 7 | 7 |
| Total | 673 | 672 |
Analysis
This month's update saw the Oracle E-Business Suite product family contain the highest number of patches at 159, accounting for 23.6% of the total patches, followed by Oracle Fusion Middleware at 153 patches, which accounted for 22.7% of the total patches.
A full breakdown of the patches for this CSPU can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication.
| Oracle Product Family | Number of Patches | Remote Exploit without Auth |
|---|---|---|
| Oracle E-Business Suite | 159 | 19 |
| Oracle Fusion Middleware | 153 | 78 |
| Oracle Hyperion | 102 | 50 |
| Oracle Siebel CRM | 63 | 26 |
| Oracle Analytics | 50 | 8 |
| Oracle Communications | 31 | 23 |
| Oracle Commerce | 27 | 16 |
| Oracle Supply Chain | 19 | 5 |
| Oracle Virtualization | 19 | 1 |
| Oracle PeopleSoft | 16 | 4 |
| Oracle Database Server | 11 | 5 |
| Oracle Enterprise Manager | 7 | 5 |
| Oracle Financial Services Applications | 6 | 2 |
| Oracle Application Testing Suite | 3 | 0 |
| Oracle Java SE | 3 | 3 |
| Oracle Autonomous Health Framework | 2 | 1 |
| Oracle Utilities Applications | 2 | 1 |
Solution
Patches are available in the September 2026 advisory for full details.
Identifying affected systems
A list of Tenable plugins to identify these vulnerabilities will appear here as they're released. This link uses a search filter to ensure that all matching plugin coverage will appear as it is released.
Get more information
- Oracle Critical Security Patch Update Advisory - September 2026
- Oracle September 2026 Critical Security Patch Update Risk Matrices
- Oracle Advisory to CVE Map
Join Tenable's Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.
Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.
Author
Learn more
- Exposure Management
- Vulnerability Management
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.tenable.com/blog/oracle-september-2026-critical-security-patch-update-addresses-672-cves