ZeroHour
Canadian Centre for Cyber Securitypublished ()ingested Canadian Centre for Cyber Security
Part of a story covered by 3 sources: “Oracle September 2026 Critical Patch Update Fixes 800+ Vulnerabilities; CCCS Relays Advisory AV26-929” — merged summary and timeline →

Oracle Corporation security advisory (AV26-929)

mediumAdvisoryimportance 40
AI summary · glm-5.3-flash

CCCS relays Oracle's September 2026 Critical Patch Update fixing vulnerabilities across WebLogic, Database, E-Business Suite, PeopleSoft, Siebel, and dozens more products.

The Canadian Centre for Cyber Security (AV26-929) relays Oracle's September 2026 Critical Security Patch Update, which addresses vulnerabilities in dozens of product families as of September 15, 2026. Affected products include Oracle WebLogic Server, Database Server, E-Business Suite, Fusion Middleware, PeopleSoft Enterprise, Siebel Applications, GraalVM, VirtualBox, Coherence, and numerous banking and communications suites. The bulletin lists no CVE identifiers and encourages administrators to review Oracle's advisory and apply patches.

  • Quarterly Oracle Critical Patch Update spanning WebLogic, Database, E-Business Suite, and Fusion Middleware.
  • Also covers PeopleSoft, Siebel, GraalVM for JDK 17/21, VirtualBox, Coherence, and banking products.
  • No specific CVE ids or exploitation details are provided in the relayed bulletin.
Full article280 words · extracted from cyber.gc.ca · click to collapse

Serial number: AV26-929
Date: September 16, 2026

As of September 15, 2026, Oracle Corporation is affected by vulnerabilities in the following products:

  • Helidon
  • Oracle Access Manager
  • Oracle Agile Engineering Data Management
  • Oracle Agile PLM
  • Oracle Agile PLM MCAD Connector
  • Oracle Application Testing Suite
  • Oracle Autonomous Health Framework
  • Oracle Banking Branch
  • Oracle Banking Corporate Lending
  • Oracle Banking Corporate Lending Process Management
  • Oracle Banking Origination
  • Oracle Banking Treasury Management
  • Oracle BI Publisher
  • Oracle Business Intelligence Enterprise Edition
  • Oracle Coherence
  • Oracle Commerce Guided Search / Oracle Commerce Experience Manager
  • Oracle Communications Cloud Native Core Security Edge Protection Proxy
  • Oracle Communications MetaSolv Solution Module - ASR
  • Oracle Communications Operations Monitor
  • Oracle Communications Service Catalog and Design
  • Oracle Communications Unified Assurance
  • Oracle Data Integrator
  • Oracle Database Server
  • Oracle E-Business Suite
  • Oracle Enterprise Manager Base Platform
  • Oracle Enterprise Manager for Fusion Middleware
  • Oracle Enterprise Manager for Oracle Database
  • Oracle Forms
  • Oracle Fusion Middleware Control
  • Oracle GraalVM Enterprise Edition
  • Oracle GraalVM for JDK 17
  • Oracle GraalVM for JDK 21
  • Oracle Hyperion Data Relationship Management
  • Oracle Hyperion Financial Management
  • Oracle Identity Manager
  • Oracle Identity Manager Connector
  • Oracle Internet Directory
  • Oracle Jdeveloper
  • Oracle Managed File Transfer
  • Oracle Middleware Common Libraries and Tools
  • Oracle Platform Security for Java
  • Oracle Product Lifecycle Analytics
  • Oracle Utilities Network Management System
  • Oracle VM VirtualBox
  • Oracle Web Services Manager
  • Oracle WebCenter Content
  • Oracle WebCenter Enterprise Capture
  • Oracle WebCenter Portal
  • Oracle WebCenter Sites
  • Oracle WebLogic Server
  • PeopleSoft Enterprise CC Common Application Objects
  • PeopleSoft Enterprise PeopleTools
  • PeopleSoft Enterprise PRTL Interaction Hub
  • Service Delivery Platform
  • Siebel Applications

The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/oracle-corporation-security-advisory-av26-929