ZeroHour
Qualys ThreatPROTECTpublished ()ingested Diksha Ojha

Oracle Critical Security Patch Update, September 2026 Review

AI summary · glm-5.3-flash

Oracle's September 2026 Critical Patch Update fixes 673 vulnerabilities, including 104 critical, with many remotely exploitable in E-Business Suite and Fusion Middleware.

Oracle released 673 security patches in its September 2026 Critical Patch Update: 104 rated critical, 503 high, and 59 medium. Oracle E-Business Suite received the most patches (159, 24% of total), with 19 exploitable without credentials including CVE-2026-83327, CVE-2026-83452, and CVE-2026-83462 at CVSS 9.8. Fusion Middleware received 153 patches with 78 remotely exploitable without authentication, and 41 patches address third-party open-source component flaws. Qualys published detection QIDs for vulnerable assets.

  • 673 total patches: 104 critical, 503 high, 59 medium severity
  • E-Business Suite tops the list with 159 patches, 19 unauthenticated-exploitable
  • Fusion Middleware: 153 patches, 78 remotely exploitable without credentials
  • 41 patches cover non-Oracle open-source components bundled in products
  • Qualys QIDs 388778-388781, 87618, 20626 detect vulnerable assets

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-83154
Unauthenticated SOAP Data Access Flaw in Oracle Siebel CRM Open UI

CVE-2026-83154 is a critical (CVSS 9.1) vulnerability in the Open UI component of Oracle Siebel CRM's End User product, affecting all supported versions from 17.0 through 26.7. It is easily exploitable by an unauthenticated attacker with network access who can reach the product's SOAP interface, requiring no privileges or user interaction. A successful attack lets the attacker create, delete, or modify critical data — or all data accessible to the Siebel CRM End User application — as well as read that data in full, with high impacts on both confidentiality and integrity (availability is not affected). Any organization running Siebel CRM within the affected version range with a network-reachable SOAP endpoint is exposed, particularly if the service is internet-facing. The flaw is not currently listed in CISA's KEV catalog, no public proof-of-concept is known, and no exploitation in the wild has been reported.

Do: Apply the Oracle Critical Patch Update that fixes CVE-2026-83154 for your Siebel Innovation Release, or upgrade to a release later than 26.7 (e.g., 26.8+). Restrict and segment network access to Siebel SOAP/EAI web service endpoints so they are not reachable from untrusted networks such as the internet. Review application and web server logs for unauthenticated SOAP requests, unexpected record creation/deletion, or anomalous data modifications that could indicate prior probing or compromise.

9.1
  • Oracle Siebel CRM (End User product, Open UI component) 17.0-26.7
moderateLow thousands of internet-exposed Siebel installations; tens of thousands of enterprise deployments overall
CVE-2026-83196
+2 in the same advisory: …83201 …83202
Privileged HTTP Takeover Flaw in Oracle Siebel CRM Deployment (Server Infrastructure)

CVE-2026-83196 is a critical (CVSS 9.1) vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM, specifically in the Server Infrastructure component, affecting supported versions 17.0 through 26.7. It is remotely exploitable over HTTP but requires a high-privileged attacker (such as an administrator with valid credentials), which lowers the realistic attack surface to insider threats, compromised admin accounts, or credential-theft-driven attacks. Because the vulnerability has a scope change (S:C), successful exploitation can significantly impact products beyond Siebel CRM Deployment, and a successful attack results in complete takeover of the Siebel CRM Deployment component with high impact to confidentiality, integrity, and availability. Organizations running affected Siebel CRM versions are exposed, particularly if the deployment/management interfaces are reachable over the network. No public proof-of-concept exists and the flaw is not on the CISA KEV list, so no active exploitation is known.

Do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83196 to all Siebel CRM deployments in the 17.0–26.7 range. Restrict network/HTTP access to the Siebel Deployment and Server Infrastructure management interfaces to trusted admin networks only, and enforce MFA on high-privileged Siebel accounts since exploitation requires elevated privileges. Review audit logs for anomalous activity by privileged accounts against deployment endpoints and verify that scope-change impacts on adjacent integrated systems have been assessed.

9.1
  • Oracle Siebel CRM (Siebel CRM Deployment, Server Infrastructure component) 17.0 - 26.7
moderate≈1,000–5,000 enterprise deployments (thousands of internet-reachable Siebel web endpoints seen in public scans, though many more are internal-only)
CVE-2026-83197
Unauthenticated Data Exposure & DoS in Oracle Siebel CRM Financial Services

CVE-2026-83197 is a critical (CVSS 9.1) flaw in the Financial Accounts component of Oracle Siebel Apps - Financial Services, affecting all supported versions from 17.0 through 26.7. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction. A successful attack allows the attacker to read critical data — up to complete access to all data accessible through Siebel Apps - Financial Services — and to cause a hang or frequently repeatable crash, resulting in complete denial of service. Integrity impact is rated as none, so the flaw is primarily a confidentiality and availability risk rather than code execution. No public proof-of-concept exists and the vulnerability is not on the CISA KEV list, so exploitation in the wild is not currently known.

Do: Check Oracle's latest Critical Patch Update for the Siebel Financial Services fix and apply it to all instances running versions 17.0-26.7. In the interim, restrict HTTP access to Siebel Apps - Financial Services endpoints (network segmentation, VPN, or WAF rules) so they are not reachable by unauthenticated users or the internet. Review logs for anomalous unauthenticated requests against the Financial Accounts component and monitor for unexplained data access or repeated crashes/hangs.

9.1
  • Oracle Siebel Apps - Financial Services (Oracle Siebel CRM, component: Financial Accounts) 17.0-26.7
moderate≈ few thousand enterprise deployments, most financial-services organizations (order of magnitude: thousands of organizations)
CVE-2026-83229
Privileged Takeover Flaw in Oracle Siebel CRM Management Console (v17.0-26.7)

A critical vulnerability (CVSS 9.1) exists in the Siebel Management Console component of Oracle Siebel CRM Deployment, affecting supported versions 17.0 through 26.7. It is easily exploitable by a high-privileged attacker with network access via HTTP, allowing them to fully compromise the Siebel CRM Deployment. The vulnerability has a scope change (S:C), meaning successful attacks can significantly impact additional products beyond the Siebel CRM Deployment component itself. Successful exploitation results in a complete takeover of the deployment with high impacts to confidentiality, integrity, and availability. There is no evidence of in-the-wild exploitation, and no public proof-of-concept is known.

Do: Apply the Oracle Critical Patch Update that remediates this flaw to all Siebel CRM deployments running versions 17.0-26.7. Restrict network access to the Siebel Management Console so it is reachable only from trusted administrative networks, and enforce least-privilege on the high-privileged accounts that could be leveraged in an attack. Audit Management Console logs for anomalous activity by high-privilege accounts and monitor for unexpected configuration or deployment changes.

9.1
  • Oracle Siebel CRM (Siebel CRM Deployment - Siebel Management Console component) 17.0 - 26.7
moderate≈1,000-10,000 enterprise deployments globally (likely only a subset with internet-exposed Management Consoles)
CVE-2026-83269
+1 in the same advisory: …83268
Unauthenticated Remote Takeover in Oracle BI Publisher (BI Platform Security)

Oracle BI Publisher, part of Oracle Analytics, contains an easily exploitable flaw in its BI Platform Security component that lets an unauthenticated attacker with HTTP network access compromise the application. Successful attacks result in a complete takeover of Oracle BI Publisher, with high impacts to confidentiality, integrity, and availability, reflected in a CVSS 3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N). Affected deployments include versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0, spanning legacy on-premises OBIEE-era releases through the current analytics release. No public proof-of-concept exists and the flaw is not on the CISA Known Exploited Vulnerabilities catalog, but the unauthenticated, network-reachable nature makes internet-facing consoles a high-priority patch target.

Do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83269 to every BI Publisher instance running 8.2.0.0.0, 12.2.1.4.0, or 26.01.0.0.0. Until patched, remove BI Publisher HTTP endpoints from internet exposure and restrict access via VPN or an authenticating reverse proxy. Review web server and BI Publisher logs for unauthenticated HTTP requests as indicators of probing or exploitation attempts.

9.8
group max
  • Oracle BI Publisher (Oracle Analytics, component: BI Platform Security)
moderate≈ several thousand internet-exposed BI Publisher/OBIEE consoles, plus an unknown number of internal enterprise deployments
CVE-2026-83282
+1 in the same advisory: …83283
Low-Privilege Takeover Flaw in Oracle BI Enterprise Edition 12.2.1.4.0

CVE-2026-83282 is a critical vulnerability (CVSS 3.1 base score 9.9) in the Platform Security component of Oracle Business Intelligence Enterprise Edition 12.2.1.4.0, part of Oracle Analytics. A low-privileged, authenticated attacker with network access via HTTP can send crafted requests that compromise the OBIEE installation and, because the scope changes, may also significantly impact additional products beyond OBIEE itself. Successful exploitation results in a complete takeover of OBIEE with high impact on confidentiality, integrity, and availability, meaning an attacker could read, alter, or destroy business analytics data and pivot to connected systems. Organizations running the affected 12.2.1.4.0 release, especially instances reachable over a network, are at risk. As of now, the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog, no public proof-of-concept is known, and no active exploitation has been reported.

Do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83282 to your OBIEE 12.2.1.4.0 environment as soon as it is available. Restrict network access to OBIEE HTTP endpoints (VPNs, allowlists, WAF rules) so only trusted users can reach the platform, and audit low-privileged accounts for suspicious privilege changes or anomalous activity. Given the scope change, also review access and logs on integrated products that trust OBIEE credentials or share its infrastructure.

9.9
group max
  • Oracle Business Intelligence Enterprise Edition (Oracle Analytics, component: Platform Security)
moderate≈ low thousands of internet-exposed OBIEE instances; total on-prem install base plausibly in the tens of thousands (estimate)
CVE-2026-83327
Unauthenticated SOAP Flaw in Oracle E-Business Suite Framework Allows Full Takeover

CVE-2026-83327 is a critical vulnerability (CVSS 9.8) in the Personalization component of Oracle Applications Framework within Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. It is easily exploitable by an unauthenticated attacker who has network access to the target via SOAP, requiring no privileges or user interaction. A successful attack allows the attacker to compromise Oracle Applications Framework and take it over, with high impact on the confidentiality, integrity, and availability of the affected system. Any organization running E-Business Suite Release 12.2 in the affected version range is potentially exposed, particularly instances with SOAP endpoints reachable from untrusted networks. There is no known public proof-of-concept, the flaw is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported as of this writing.

Do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83327 to all E-Business Suite 12.2.3-12.2.15 environments as a top priority given the unauthenticated, network-exploitable nature of the flaw. Until patched, restrict or block unauthenticated network access to SOAP endpoints on the EBS web tier using firewall/WAF rules, and allow-list only trusted integration sources. Review HTTP/SOAP access logs for anomalous unauthenticated requests targeting Applications Framework Personalization services, and treat any confirmed compromise as a full-takeover incident.

9.8
  • Oracle E-Business Suite (Oracle Applications Framework, Personalization component) 12.2.3-12.2.15
moderate≈1,000-10,000 internet-exposed E-Business Suite web tiers, plus a larger population of internal-only deployments
CVE-2026-83452
Unauthenticated Takeover Flaw in Oracle EBS Document Management and Collaboration

CVE-2026-83452 is a critical (CVSS 9.8) flaw in the Internal Operations component of the Oracle Document Management and Collaboration product within Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction, and successful attacks allow complete takeover of the Document Management and Collaboration component with high impact to confidentiality, integrity, and availability. Organizations running affected EBS releases that expose these services to a network — especially internet-facing HTTP endpoints — are at risk of full compromise of sensitive documents and collaboration data. The flaw is addressed in Oracle's Critical Patch Update cycle, but the specific flaw type (e.g., injection or deserialization) was not disclosed by Oracle. No public proof-of-concept or confirmed in-the-wild exploitation has been reported, and the CVE is not on the CISA Known Exploited Vulnerabilities catalog.

Do: Apply the Oracle Critical Patch Update that remediated CVE-2026-83452 to all EBS 12.2.3-12.2.15 environments running Document Management and Collaboration, prioritizing internet-facing instances. Restrict HTTP access to EBS DMC/Internal Operations endpoints via firewall rules or VPN so they are not reachable unauthenticated from untrusted networks. Review access logs for anomalous unauthenticated requests to the affected component and rotate credentials for accounts associated with it if compromise is suspected.

9.8
  • Oracle E-Business Suite - Oracle Document Management and Collaboration (Internal Operations component) 12.2.3-12.2.15
moderatelikely low thousands of internet-exposed EBS instances; tens of thousands of total EBS deployments (estimate)
CVE-2026-83462
Unauthenticated Takeover in Oracle EBS Mobile Application Server (MWA Terminal Server)

CVE-2026-83462 is a critical (CVSS 9.8) vulnerability in the MWA Terminal Server component of the Oracle Mobile Application Server, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. An unauthenticated remote attacker who can reach the MWA Terminal Server's TCP port over the network can exploit the flaw without any user interaction or credentials, and a successful attack results in a complete takeover of the Oracle Mobile Application Server with high impact to confidentiality, integrity, and availability. Because exploitation is described as easy and requires no privileges, any EBS environment running an affected version with the MWA service reachable (especially from the internet) is at serious risk of full server compromise. Organizations running EBS 12.2.3-12.2.15 in warehouse, manufacturing, or mobile data-collection deployments are the primary affected population. There is no known public proof-of-concept and the flaw is not on the CISA KEV list, so exploitation status is currently none known.

Do: Apply Oracle's Critical Patch Update that fixes CVE-2026-83462 to all EBS 12.2.3-12.2.15 environments running the Mobile Application Server. Until patched, block external access to the MWA Terminal Server TCP port at the firewall and restrict it to trusted internal networks or VPN clients, or shut down the MWA service if mobile/warehouse functionality is not in use. Review logs for unexpected TCP connections and anomalous terminal sessions on the MWA port to rule out prior exploitation.

9.8
  • Oracle E-Business Suite - Oracle Mobile Application Server (MWA Terminal Server component) 12.2.3-12.2.15
moderate≈ low thousands of internet-reachable MWA Terminal Server endpoints, within a broader population of tens of thousands of on-premises EBS 12.2 deployments
Full article571 words · extracted from threatprotect.qualys.com · click to collapse

Oracle released its September edition of Critical Security Patch Update. The update received patches for 673 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.

Out of the 673 security updates published, total 104 (15%) vulnerabilities are rated critical, 503 are rated as high (75%), and 59 rated as medium.

In this Oracle Critical Security Patch Update, Oracle E-Business Suite received the highest number of patches, 159, constituting about 24% of the total patches released.

41 of the 673 (about 6%) security patches provided by the September Critical Security Patch Update are for non-Oracle CVEs, such as open-source components included in and exploitable within Oracle product distributions.

This batch of security patches received 13 updates for Oracle Database products. The following is the product-wise distribution:

  • 11 new security updates for Oracle Database Server with a maximum reported CVSS Base Score of 8.8.
      • 2 of these updates apply to client-only deployments of the Oracle Database.
  • 2 new security updates for Oracle Autonomous Health Framework with a maximum reported CVSS Base Score of 7.5.

The complete list of Oracle product families and the no of patches issued are listed below:

Oracle Product Family No. of Patches Remote Exploit without Authentication
Oracle E-Business Suite 159 19
Oracle Fusion Middleware 153 78
Oracle Hyperion 102 50
Oracle Siebel CRM 63 26
Oracle Analytics 50 8
Oracle Communications 31 23
Oracle Commerce 27 16
Oracle Supply Chain 19 5
Oracle Virtualization 19 1
Oracle PeopleSoft 16 4
Oracle Database Server 11 5
Oracle Enterprise Manager 7 5
Oracle Financial Services Applications 6 2
Oracle Application Testing Suite 3 0
Oracle Java SE 3 3
Oracle Autonomous Health Framework 2 1
Oracle Utilities Applications 2 1

Notable Oracle Vulnerabilities Patched

Oracle E-Business Suite

This Critical Security Patch Update for Oracle E-Business Suite received 159 security patches. Out of these, 19 vulnerabilities can be exploited over a network without user credentials.

CVE-2026-83327, CVE-2026-83452, and CVE-2026-83462 have critical severity ratings with a CVSS score of 9.8.

Oracle Fusion Middleware

This Critical Security Patch Update for Oracle Fusion Middleware received 153 security patches. Out of these, 78 vulnerabilities can be exploited over a network without user credentials.

A total of 67 CVEs affecting different products of Oracle Fusion Middleware have critical severity ratings.

Oracle Hyperion

This Critical Security Patch Update for Oracle Hyperion received 102 security patches. Out of these, 50 vulnerabilities can be exploited over a network without user credentials.

A total of 14 CVEs affecting various Oracle Hyperion products have critical severity ratings.

Oracle Siebel CRM

This Critical Security Patch Update for Oracle Siebel CRM received 63 security patches. Out of these, 26 vulnerabilities can be exploited over a network without user credentials.

CVE-2026-83197, CVE-2026-83196, CVE-2026-83201, CVE-2026-83202, CVE-2026-83229, and CVE-2026-83154 have critical severity ratings.

Oracle Analytics

This Critical Security Patch Update for Oracle Analytics received 50 security patches. Out of these, 8 vulnerabilities can be exploited over a network without user credentials.

CVE-2026-83282, CVE-2026-83269, CVE-2026-83283, and CVE-2026-83268 have critical severity ratings.

Visit the Oracle Critical Security Patch Update August 2026 (CPUSEP2026) page to read descriptions of each vulnerability and the systems it affects.

Customers can scan their network with QIDs 388781, 388780, 388779, 388778, 388773, 87618, and 20626 to detect vulnerable assets.

Please continue to follow Qualys Threat Protection for more coverage of the latest vulnerabilities.

References:
https://www.oracle.com/security-alerts/cspuaug2026.html

Text extracted automatically; images, tables and formatting may be missing. Original: https://threatprotect.qualys.com/2026/09/16/oracle-critical-security-patch-update-september-2026-review/