ZeroHour
SecurityWeekpublished ()ingested Ionut Arghire

Oracle Patches 800+ Vulnerabilities in September 2026 Security Update

highAdvisoryimportance 55
AI summary · glm-5.3-flash

Oracle's September 2026 Critical Patch Update fixes 800+ vulnerabilities, including over 100 critical flaws and 240+ remotely exploitable without authentication.

Oracle released 673 new security patches in its September 2026 Critical Security Patch Update, resolving 672 unique CVEs across 17 risk matrices plus 130+ additional CVEs. More than 100 flaws are critical severity and over 240 are remotely exploitable without authentication. Oracle E-Business Suite received the largest batch with 159 patches, followed by Fusion Middleware (153, including 78 unauthenticated remote flaws) and Hyperion (102). Oracle reports no exploitation of these specific flaws but warns attackers routinely exploit unpatched Oracle products.

  • 672 unique CVEs across 17 risk matrices, plus 130+ additional CVEs resolved
  • Over 100 critical flaws and 240+ remotely exploitable without authentication
  • E-Business Suite: 159 patches (19 unauthenticated); Fusion Middleware: 153 (78 unauthenticated)
  • No exploitation reported for these flaws; Oracle urges immediate patching
  • Also covers Siebel, Analytics, Database Server, Java SE, Virtualization, PeopleSoft
Full article333 words · extracted from securityweek.com · click to collapse

Oracle on Tuesday announced the release of 673 new security patches as part of its September 2026 Critical Security Patch Update (CSPU).

The security updates appear to resolve more than 800 vulnerabilities: there are 672 unique CVEs in the 17 risk matrices included in the September 2026 CSPU advisory, but Oracle also notes that more than 130 additional CVEs have been resolved with the patches for other flaws.

More than 100 of the newly addressed security defects are critical-severity flaws, and over 240 are remotely exploitable without authentication.

Oracle E-Business Suite received 159 security patches, the largest batch of the CSPU. 19 of the vulnerabilities can be exploited remotely without authentication.

Fusion Middleware followed closely, receiving 153 patches, including fixes for 78 unauthenticated, remotely exploitable flaws. Hyperion was third, with 102 patches (50 remotely exploitable without authentication).

Oracle also rolled out a significant number of patches for Siebel CRM (63), Analytics (50), Communications (31), Commerce (27), Supply Chain (19), Virtualization (19), and PeopleSoft (16).

Advertisement. Scroll to continue reading.

The Communications update stands out, as half of its patches resolve more than 125 additional CVEs.

Other Oracle products that received patches this month include Database Server, Enterprise Manager, Financial Services Applications, Application Testing Suite, Java SE, Autonomous Health Framework, and Utilities Applications.

Oracle makes no mention of any of these vulnerabilities being exploited in the wild, but warns users that threat actors are regularly exploiting flaws in its products, urging customers to apply the updates as soon as possible.

“In some instances, it has been reported that attackers have been successful because targeted customers had failed to apply available Oracle patches. Oracle therefore strongly recommends that customers remain on actively-supported versions and apply security patches without delay,” Oracle notes.

Related: $1 Million Sandbox Challenge Uncovers Linux Kernel Flaws

Related: Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases

Related: Thai Broadband Provider Hacked via Fortinet Vulnerability

Related: Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/oracle-patches-800-vulnerabilities-in-september-2026-security-update/