ZeroHour
Cyber Security Newspublished ()ingested Guru Baran
Part of a story covered by 2 sources: “Oracle's September 2026 Critical Patch Update Ships 673 Patches Covering 800+ CVEs, Including 100+ Critical and 240+ Remotely Exploitable Flaws” — merged summary and timeline →

Oracle Critical Security Update – 673 Vulnerabilities Patched Across Product Families

highAdvisoryimportance 58CVE-2026-21962
AI summary · glm-5.3-flash

Oracle's September 2026 Critical Patch Update ships 673 patches across 17 product families, including 100+ critical and 240+ remotely exploitable flaws.

Oracle's September 2026 Critical Security Patch Update ships 673 patches covering 672 unique CVEs, with more than 130 additional CVEs resolved through bundled fixes, pushing the effective total past 800. Over 100 flaws are critical severity and more than 240 are remotely exploitable without authentication. Oracle E-Business Suite received 159 fixes, Fusion Middleware 153 (78 unauthenticated and network-exploitable), and Hyperion 102. No in-the-wild exploitation of these specific flaws is reported, but Oracle cites CISA's earlier 72-hour remediation order for actively exploited CVE-2026-21962 (CVSS 10.0).

  • 673 patches across 17 product families; effective remediation total exceeds 800 CVEs including bundled third-party fixes.
  • Fusion Middleware gets 153 patches with 78 remotely exploitable without authentication; E-Business Suite receives 159.
  • Hyperion receives 102 patches, half unauthenticated; Siebel, Analytics, Communications and other families also patched.
  • Oracle warns attackers exploit unpatched systems, citing CISA's 72-hour order for CVE-2026-21962 (CVSS 10.0).
  • Defenders should prioritize internet-exposed Fusion Middleware, E-Business Suite, and Hyperion deployments.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-21962
Unauthenticated Access Control Bypass in Oracle HTTP Server and WebLogic Proxy Plug-in

CVE-2026-21962 is an improper access control flaw (CWE-284) in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in (components: the plug-in for Apache HTTP Server and the plug-in for IIS), part of Oracle Fusion Middleware. An unauthenticated attacker with network access via HTTP can trivially exploit it, and the scope-change designation means a successful attack can significantly impact additional products beyond the plug-in itself. The attacker gains unauthorized access to critical data (potentially all accessible data) as well as the ability to create, delete, or modify critical data, reflected in the maximum CVSS 10.0 score with high confidentiality and integrity impacts and no availability impact. Organizations running the affected versions - 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0 for Oracle HTTP Server and the Apache plug-in, and 12.2.1.4.0 only for the IIS plug-in - especially those with internet-facing Apache/IIS/OHS front ends proxying WebLogic applications, are exposed. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-24, and EPSS assigns a 42% probability of exploitation within 30 days, though no public proof-of-concept is known.

Do: Apply the fixes from Oracle's January 2026 quarterly update (advisory AV26-042) or later for Oracle HTTP Server and the WebLogic Server Proxy Plug-in on all affected versions - 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0 (IIS plug-in affected at 12.2.1.4.0 only). Prioritize internet-facing OHS, Apache and IIS front ends per CISA BOD 26-04 and the KEV required actions, and where patching is delayed, restrict HTTP access to trusted networks and review logs for signs of unauthorized data access or modification.

10.042% KEV
  • Oracle HTTP Server (Oracle Fusion Middleware) 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0
  • Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0
  • Oracle WebLogic Server Proxy Plug-in for IIS 12.2.1.4.0
large~10,000-100,000 internet-exposed Oracle HTTP Server / WebLogic proxy front ends
Full article605 words · extracted from cybersecuritynews.com · click to collapse

Oracle has released one of its largest monthly security bundles to date, shipping 673 new security patches in its September 2026 Critical Security Patch Update (CSPU) to close serious flaws spanning its enterprise software portfolio.

The advisory, published on September 15, spans 17 product families and includes more than 100 critical-severity vulnerabilities, with over 240 flaws remotely exploitable without authentication, meaning an attacker can weaponize them over a network without valid credentials.

While the headline figure is 673 patches, the true scope is broader. Oracle’s advisory contains 672 unique CVEs across its published risk matrices, but the vendor notes that more than 130 additional CVEs have been quietly resolved through patches bundled for other flaws, pushing the effective total past 800 vulnerabilities remediated in a single release.

This blurs the traditional line between Oracle’s lighter monthly CSPUs and its heavier quarterly Critical Patch Updates (CPUs), a trend that has accelerated throughout 2026.

Oracle September Security Update

The CSPU is a relatively new addition to Oracle’s security program, first introduced in May 2026 as a targeted, high-priority release designed to be easier to deploy with minimal operational disruption.

These updates are issued on the third Tuesday of February, March, May, June, August, September, November, and December, filling the gaps between the cumulative quarterly CPUs released each January, April, July, and October.

According to the security advisory published by Oracle, the goal is to shrink the window during which known vulnerabilities remain exploitable in customer environments. The next scheduled releases are a CPU on October 20, followed by CSPUs on November 17 and December 15.

Oracle E-Business Suite absorbed the largest share of fixes with 159 patches, 19 of them remotely exploitable without authentication.

Fusion Middleware followed closely with 153 patches, a particularly alarming batch given that 78 of those flaws are unauthenticated and network-exploitable, the kind of exposure that maps directly to internet-facing enterprise infrastructure. Hyperion ranked third with 102 patches, half of which require no authentication to exploit.

Beyond the top three, Oracle distributed substantial fixes across Siebel CRM (63), Analytics (50), Communications (31), Commerce (27), Supply Chain (19), Virtualization (19), and PeopleSoft (16).

The Communications update is notable because roughly half of its patches resolve more than 125 additional CVEs, largely rooted in bundled third-party components.

Additional families receiving attention include Database Server, Enterprise Manager, Financial Services Applications, Application Testing Suite, Java SE, Autonomous Health Framework, and Utilities Applications.

Oracle makes no mention of any of these specific September vulnerabilities being exploited in the wild, but the company issued a familiar and pointed warning.

It continues to receive reports of attackers succeeding against organizations that simply failed to apply patches already available a recurring pattern where the gap between disclosure and remediation becomes the attacker’s entry point.

That risk is not theoretical: earlier in 2026, CISA gave federal agencies just 72 hours to remediate an actively exploited Oracle flaw (CVE-2026-21962, CVSS 10.0) that had been patched months earlier.

Given the volume of unauthenticated, remotely exploitable flaws in this release, security teams should prioritize internet-exposed Fusion Middleware, E-Business Suite, and Hyperion deployments first.

Oracle strongly urges customers to remain on actively supported versions and to apply the patches without delay. Full patch availability documents and per-product risk matrices are available in the official September 2026 CSPU advisory.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Guru Baranhttps://cybersecuritynews.com

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/oracle-security-update-673-vulnerabilities/