ZeroHour
CSO Onlinepublished ()ingested

Oracle’s September patches put Fusion Middleware back in the hot seat

AI summary · glm-5.3-flash

Oracle's September 2026 CPU ships 673 patches including six CVSS 10.0 flaws in Fusion Middleware and Hyperion, none exploited in the wild.

Oracle's September 2026 Critical Security Patch Update delivers 673 patches across 17 product families, led by E-Business Suite with 159 fixes and Fusion Middleware with 153. Six CVSS 10.0 vulnerabilities in Access Manager, Forms, Internet Directory, Platform Security for Java, WebLogic Server, and Hyperion are remotely exploitable without authentication, and Oracle reports none exploited in the wild. Now patching monthly, Oracle urged immediate deployment and warned that unsupported releases are not tested for these flaws.

  • 673 new security patches spanning 17 Oracle product families
  • Six CVSS 10.0 flaws remotely exploitable without authentication
  • 13 additional CVSS 9.9 Fusion Middleware bugs require low privileges
  • Oracle shifted from quarterly to monthly patching cadence
  • Oracle warns of ongoing attacks on customers who skipped prior fixes

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-71133
+2 in the same advisory: …71163 …73945
Unauthenticated Takeover Flaw in Oracle Access Manager Authentication Engine (CVSS 10.0)

CVE-2026-71133 is a critical vulnerability in the Authentication Engine component of Oracle Access Manager (OAM), part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.1.0. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction, and successful attacks result in complete takeover of Oracle Access Manager. Because the CVSS vector includes a scope change (S:C), compromise of OAM can significantly impact additional products beyond the vulnerable component itself. Any organization exposing an affected OAM deployment — which commonly fronts internet-facing single sign-on and authentication portals — is at risk of full confidentiality, integrity, and availability impact. No public proof of concept is known and the flaw is not on the CISA KEV list, but the unauthenticated, network-exploitable nature makes patching urgent.

Do: Apply the Oracle Critical Patch Update that remediates CVE-2026-71133 to affected OAM 12.2.1.4.0 and 14.1.2.1.0 deployments as an emergency change, prioritizing any instance reachable from the internet. Until patched, restrict network access to OAM authentication endpoints (VPNs, IP allowlists, WAF rules) and enforce TLS so the HTTP attack path is closed. Review OAM and federation logs for unauthenticated anomalous requests or unexpected administrative changes that could indicate attempted compromise.

10.0
group max
  • Oracle Access Manager (Oracle Fusion Middleware, Authentication Engine component) 12.2.1.4.0, 14.1.2.1.0
large≈10,000–50,000 internet-exposed OAM instances across thousands of enterprise organizations (estimate)
CVE-2026-73948
+1 in the same advisory: …83039
Authenticated Takeover Flaw in Oracle WebCenter Portal Composer

CVE-2026-73948 is a critical (CVSS 9.9) vulnerability in the Composer component of Oracle WebCenter Portal, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. A remote attacker holding only low-privileged credentials can exploit it over HTTP with no user interaction, and successful attacks result in a complete takeover of the WebCenter Portal deployment. The CVSS scope-change designation (S:C) means compromises can also significantly impact additional products beyond WebCenter Portal itself, with high confidentiality, integrity, and availability consequences. Only organizations running the two affected WebCenter Portal versions are exposed, and exploitation requires an authenticated session, so attackers would typically chain it with stolen or weak low-privilege credentials. No public proof-of-concept exists, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no exploitation in the wild has been reported.

Do: Apply the Oracle Critical Patch Update that remedies this CVE to all WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 installations as soon as it is available, prioritizing any instance reachable over a network. Enforce strong authentication and least-privilege role assignments for portal users, and audit low-privilege accounts for suspicious activity or privilege changes. Because the flaw carries a scope change, also review and harden adjacent Fusion Middleware products integrated with the portal after patching.

9.9
  • Oracle WebCenter Portal (Oracle Fusion Middleware, Composer component) 12.2.1.4.0
  • Oracle WebCenter Portal (Oracle Fusion Middleware, Composer component) 14.1.2.0.0
niche≈ hundreds to a few thousand deployments worldwide, with likely only hundreds internet-exposed
CVE-2026-82997
+2 in the same advisory: …82998 …82999
Low-Privilege Takeover in Oracle Service Delivery Platform via T3/IIOP

CVE-2026-82997 is a critical (CVSS 9.9) vulnerability in the Messaging Enabler component of Oracle's Service Delivery Platform, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. A remote attacker with only low-privileged (authenticated) access to the T3 or IIOP network interfaces can exploit the flaw easily and completely take over the Service Delivery Platform, and because the vulnerability has a scope change, successful attacks can also significantly impact additional products, with high impact to confidentiality, integrity, and availability. The affected deployments are Oracle Communications Service Delivery Platform installations at communications service providers, primarily telecom operators running carrier-grade messaging infrastructure. No public proof-of-concept code is known and the flaw is not on CISA's Known Exploited Vulnerabilities catalog, so exploitation in the wild is not currently evidenced.

Do: Apply the Oracle Critical Patch Update that remediates CVE-2026-82997 to all Service Delivery Platform 12.2.1.4.0 and 14.1.2.0.0 installations. Until patched, block or tightly firewall the T3 and IIOP listeners (commonly WebLogic ports such as 7001/7002 and the IIOP port) at the network perimeter so only trusted administrative subnets can reach them, and consider disabling IIOP entirely if unused. Review low-privileged account activity and WebLogic/T3 session logs for anomalous connections, and verify with external scanning that no SDP protocol ports are exposed to the internet.

9.9
  • Oracle Fusion Middleware / Service Delivery Platform (component: Messaging Enabler) 12.2.1.4.0, 14.1.2.0.0
nichelikely hundreds to low thousands of telecom-operator deployments worldwide
CVE-2026-83020
Unauthenticated Takeover Flaw in Oracle Platform Security for Java (Fusion Middleware)

CVE-2026-83020 is a critical (CVSS 3.1 base score 10.0) vulnerability in the Centralized Thirdparty Jars component of Oracle Platform Security for Java (OPSS), part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges and no user interaction. Successful exploitation results in complete takeover of Oracle Platform Security for Java, and because of a scope change, attacks may significantly impact additional products beyond OPSS itself, with full impact to confidentiality, integrity, and availability. Organizations running WebLogic Server or other Fusion Middleware deployments on the affected OPSS versions are exposed wherever the relevant HTTP endpoints are reachable. As of now, the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known.

Do: Apply the Oracle Critical Patch Update (CPU) that remediates CVE-2026-83020 to all OPSS installations on 12.2.1.4.0 and 14.1.2.0.0, prioritizing any systems with HTTP endpoints exposed to untrusted networks. Restrict network access to administrative and OPSS-related HTTP endpoints so only trusted hosts can reach them, and monitor logs for unauthenticated HTTP requests targeting Fusion Middleware/OPSS paths until patching is complete.

10.0
  • Oracle Platform Security for Java (Oracle Fusion Middleware, component: Centralized Thirdparty Jars) 12.2.1.4.0, 14.1.2.0.0
large≈ tens of thousands of internet-exposed Oracle Fusion Middleware/WebLogic hosts, plus a larger unknown number of internal enterprise deployments
CVE-2026-83021
Unauthenticated HTTP Takeover Flaw in Oracle WebLogic Server Web Container

CVE-2026-83021 is a critical (CVSS 3.1 base score 10.0) vulnerability in the Web Container component of Oracle WebLogic Server, part of Oracle Fusion Middleware. It is triggered remotely by an unauthenticated attacker sending crafted requests over HTTP to an affected WebLogic instance, requiring no privileges or user interaction. A successful exploit results in a complete takeover of Oracle WebLogic Server, and because the CVSS scope is changed, successful attacks may also significantly impact additional products beyond WebLogic itself. The supported affected versions are 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0. As of this writing, the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, though WebLogic's history as a high-value target makes prompt patching essential.

Do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83021 to all WebLogic Server installations running 12.2.1.4.0, 14.1.1.0.0, or 14.1.2.0.0 as soon as it is available, prioritizing any instance reachable over HTTP. Until patched, restrict network access to WebLogic HTTP/Admin listen ports (e.g., 7001/7002) to trusted sources via firewall rules, and review logs for unauthenticated anomalous HTTP requests against the Web Container. Also assess connected products and services, since successful attacks can impact systems beyond WebLogic itself.

10.0
  • Oracle WebLogic Server (Oracle Fusion Middleware, component: Web Container)
large≈ tens of thousands of internet-exposed WebLogic instances, plus a larger unknown population of internal enterprise deployments
CVE-2026-83031
Privilege Escalation to Full Takeover in Oracle WebCenter Sites (CVSS 9.9)

Oracle WebCenter Sites, a component of Oracle Fusion Middleware, contains an easily exploitable flaw that allows a low-privileged authenticated attacker with network access via HTTP to compromise the product and achieve a complete takeover of the WebCenter Sites installation. The vulnerability carries a CVSS 3.1 base score of 9.9 with a scope change, meaning successful attacks on WebCenter Sites can significantly impact additional products beyond the initially affected component. Successful exploitation results in high impact to the confidentiality, integrity, and availability of the compromised system. Affected deployments are Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0. There is no known public proof-of-concept and no evidence of in-the-wild exploitation; the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog.

Do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83031 to WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 as the highest priority. Until patched, restrict HTTP access to WebCenter Sites (especially administrative and content-management interfaces) via VPN or IP allowlisting, enforce least privilege on contributor accounts, and review authentication and audit logs for anomalous activity by low-privileged users. Because the vulnerability has a scope change, also verify patch levels and inspect logs on adjacent Fusion Middleware products that share the same infrastructure.

9.9
  • Oracle WebCenter Sites (Oracle Fusion Middleware)
moderateLikely on the order of a few thousand internet-reachable WebCenter Sites instances worldwide; total enterprise deployments unknown
CVE-2026-83038
Low-Privilege Authenticated RCE in Oracle WebLogic Server TopLink Integration

CVE-2026-83038 is a critical (CVSS 9.9) vulnerability in the TopLink Integration component of Oracle WebLogic Server, part of Oracle Fusion Middleware. A remote attacker who already holds low-privileged credentials for the server and has HTTP network access can exploit the flaw easily, and a successful attack results in a complete takeover of Oracle WebLogic Server. The CVSS vector includes a scope change (S:C), meaning compromise of WebLogic can significantly impact additional products beyond the vulnerable component itself, with high impact on confidentiality, integrity, and availability. Affected deployments are those running WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, or 15.1.1.0.0. As of this analysis, the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so there is no confirmed in-the-wild exploitation.

Do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83038 to all WebLogic Server installations running 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, or 15.1.1.0.0. Because exploitation requires only low-privileged HTTP access, restrict management and application HTTP endpoints to trusted networks/VPNs, enforce strong authentication and least-privilege on all WebLogic accounts, and audit low-privilege accounts for abuse. Review servers for signs of post-exploitation such as unexpected deployments, scheduled jobs, or new OS-level users, since successful attacks lead to full server takeover with scope change to adjacent products.

9.9
  • Oracle WebLogic Server (Oracle Fusion Middleware, component: TopLink Integration) 12.2.1.4.0
  • Oracle WebLogic Server (Oracle Fusion Middleware, component: TopLink Integration) 14.1.1.0.0
  • Oracle WebLogic Server (Oracle Fusion Middleware, component: TopLink Integration) 14.1.2.0.0
  • +1 more
largeOn the order of tens of thousands of internet-exposed WebLogic servers (roughly 10,000–100,000), plus a substantial internal enterprise estate
CVE-2026-83059
+4 in the same advisory: …83056 …83057 …83058 …83055
Unauthenticated LDAP Flaw Allows Full Takeover of Oracle Internet Directory

CVE-2026-83059 is a critical (CVSS 10.0) vulnerability in the OID LDAP Server component of Oracle Internet Directory, part of Oracle Fusion Middleware, affecting supported versions 12.2.1.4.0 and 14.1.2.1.0. An unauthenticated remote attacker with network access to the LDAP service can exploit the flaw with low complexity, requiring no privileges or user interaction. Successful exploitation results in a complete takeover of Oracle Internet Directory with high impact to confidentiality, integrity, and availability, and because the scope changes, successful attacks may also significantly impact additional products beyond OID itself. Organizations running the affected OID versions with LDAP reachable by untrusted networks are the primary at-risk population. No public proof of concept is known, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported to date.

Do: Apply the Oracle Critical Patch Update that remediates this vulnerability to all Oracle Internet Directory instances running 12.2.1.4.0 or 14.1.2.1.0, prioritizing any OID LDAP endpoints reachable from untrusted networks. Restrict network access to OID LDAP ports so only trusted directory clients can connect, and verify no unauthenticated anomalous LDAP activity has occurred on affected servers.

10.0
group max
  • Oracle Internet Directory (Oracle Fusion Middleware, OID LDAP Server component) 12.2.1.4.0, 14.1.2.1.0
moderate≈ a few thousand internet-exposed OID LDAP endpoints, out of a larger base of roughly tens of thousands of internal enterprise deployments (clearly an estimate)
CVE-2026-83099
Unauthenticated HTTP Takeover of Oracle Forms in Fusion Middleware (CVSS 10.0)

CVE-2026-83099 is a critical (CVSS 3.1 base score 10.0) unauthenticated vulnerability in the Forms Services client/server and character-mode components of Oracle Forms, part of Oracle Fusion Middleware. It is triggered remotely over HTTP by an attacker with no credentials and no user interaction, and successful exploitation results in a complete takeover of Oracle Forms with full impact to confidentiality, integrity, and availability. The CVSS vector includes a scope change (S:C), meaning attacks against the vulnerable Forms component can also significantly impact additional products on the compromised host. Affected deployments are Oracle Forms 12.2.1.19.0 and 14.1.2.0.0. No public proof of concept exists, the flaw is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported to date.

Do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83099 to all Oracle Forms 12.2.1.19.0 and 14.1.2.0.0 installations as an emergency change, prioritizing any Forms Services endpoints reachable over the network. Remove internet exposure for Forms servlets and restrict access to trusted networks or VPN, and place the service behind an authenticating reverse proxy where possible. Review HTTP access logs for unauthenticated requests to Forms Services endpoints and watch for anomalous process or file activity on Forms hosts, since the scope change means adjacent products on the same server may be impacted after compromise.

10.0
  • Oracle Fusion Middleware / Oracle Forms (Forms Services, C/S, Charmode) 12.2.1.19.0, 14.1.2.0.0
moderate≈ low thousands of internet-exposed Oracle Forms endpoints, plus a larger unknown population of internal enterprise deployments
CVE-2026-87230
Unauthenticated Critical Flaw in Oracle Hyperion Financial Management Security Component

CVE-2026-87230 is a flaw in the Security component of Oracle Hyperion Financial Management, affecting supported version 11.2.26.0.000. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges and no user interaction. Successful attacks allow unauthorized creation, deletion, or modification of critical data — or all data accessible to Oracle Hyperion Financial Management — as well as unauthorized read access to that data, and because of a scope change, the impact can extend beyond Hyperion Financial Management to additional products. The vulnerability carries a maximum CVSS 3.1 base score of 10.0, driven by high confidentiality and integrity impacts. No public proof of concept is known, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been reported to date.

Do: Apply the Oracle patch for this issue as soon as it is available via Oracle's Critical Patch Update for Hyperion 11.2.x, since 11.2.26.0.000 is the only listed affected version. Until patched, restrict network access to Hyperion Financial Management HTTP endpoints — remove internet exposure and place the service behind a VPN or allow-listed reverse proxy — and monitor authentication and Security component logs for unauthenticated access attempts. Verify that you are not running the affected 11.2.26.0.000 build on any production or DR instance.

10.0
  • Oracle Hyperion Financial Management 11.2.26.0.000
moderatelikely on the order of a few thousand installations (low thousands of internet-reachable instances; unclear how many more exist on internal networks)
Full article530 words · extracted from csoonline.com · click to collapse

Oracle’s September 2026 Critical Security Patch Update has arrived with 673 new security patches spanning 17 Oracle product families, with Oracle E-Business Suite accounting for the largest share at 159 patches, followed by Fusion Middleware with 153. Of these, 19 E-Business Suite vulnerabilities and 78 Fusion Middleware vulnerabilities can be remotely exploited without authentication.

Other product categories with 50 or more issues fixed in the rollout include Oracle Database Server, Oracle Communications, and Oracle Analytics.

Oracle recently accelerated its patching rhythm from quarterly to monthly. It advised customers to apply the September patches immediately, warning that it continues to receive reports of successful attacks on its software where customers had not applied available fixes.

Five max-severity flaws sit in Fusion Middleware

The September update addresses five critical vulnerabilities carrying the maximum CVSS score of 10.0 within Fusion Middleware.

They affect Oracle Access Manager (CVE-2026-71133), Oracle Forms (CVE-2026-83099), Oracle Internet Directory (CVE-2026-83059), Oracle Platform Security for Java (CVE-2026-83020), and Oracle WebLogic Server (CVE-2026-83021).

All five are remotely exploitable without authentication over the network; attacking them is of low complexity and requires neither privileges nor user interaction.

The update also addressed a sixth CVSS 10.0 vulnerability, this one in Oracle Hyperion Financial Management (CVE-2026-87230); it too can be remotely exploited without authentication.

The update also includes 13 Fusion Middleware bugs with a CVSS score of 9.9, just below the maximum severity. These include CVE-2026-71163 and CVE-2026-73945 in Oracle Access Manager, CVE-2026-83055, CVE-2026-83057 and CVE-2026-83056 in Oracle Internet Directory, CVE-2026-83058, CVE-2026-73948 and CVE-2026-83039 in Oracle WebCenter Portal, CVE-2026-82999, CVE-2026-82997 and CVE-2026-82998 in Service Delivery Platform, and one each in Oracle WebCenter Sites (CVE-2026-83031) and Oracle WebLogic Server (CVE-2026-83038).

None of these are remotely exploitable without authentication. However, they require low privileges, remain network-accessible and can have high confidentiality and integrity impacts.

Oracle did not mark any of the six CVSS 10.0 and 13 CVSS 9.9 vulnerabilities as exploited in the wild.

Fusion Middleware has featured heavily in Oracle’s recent patch cycles too. Its July update addressed 10 CVSS 10.0 vulnerabilities, highlighting the product family’s recurring exposure to maximum-severity flaws.

Oracle’s patching message is as important as the patches

Until patches can be deployed, Oracle said, customers may reduce exposure by blocking network protocols required for an attack or removing unnecessary privileges and package access. However, it cautioned, these measures can break application functionality and should be tested on non-production systems. They are not to be considered long-term solutions because they do not address the underlying vulnerabilities, the company said in its September critical patch update advisory.

It also included a warning for organizations running older Oracle releases. The fixes are provided only for supported versions, the company said, adding that “Product releases that are not under Premier Support or Extended Support are not tested for the presence of vulnerabilities addressed by this Critical Security Patch Update.”

Also, for organizations that have skipped earlier security updates, Oracle advises reviewing previous CSPUs and quarterly Critical Patch Updates rather than assuming the September releases covers the backlog.

This article first appeared on CIO.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.csoonline.com/article/4222875/oracles-september-patches-put-fusion-middleware-back-in-the-hot-seat-2.html