Oracle Patches 800+ Vulnerabilities in September 2026 Security Update
Oracle's September 2026 Critical Patch Update fixes 800+ vulnerabilities, including over 100 critical flaws and 240+ remotely exploitable without authentication.
Oracle released 673 new security patches in its September 2026 Critical Security Patch Update, resolving 672 unique CVEs across 17 risk matrices plus 130+ additional CVEs. More than 100 flaws are critical severity and over 240 are remotely exploitable without authentication. Oracle E-Business Suite received the largest batch with 159 patches, followed by Fusion Middleware (153, including 78 unauthenticated remote flaws) and Hyperion (102). Oracle reports no exploitation of these specific flaws but warns attackers routinely exploit unpatched Oracle products.
Oracle Critical Patch Update, August 2026 Security Update Review
Oracle's August 2026 Critical Patch Update fixes 943 vulnerabilities; Oracle Fusion Middleware and Hyperion received the most patches at 262.
Oracle released its August 2026 Critical Patch Update, addressing 943 security vulnerabilities across multiple product families, including third-party components bundled in Oracle products. Oracle Fusion Middleware and Oracle Hyperion received the highest number of fixes with 262 patches. Several of the addressed vulnerabilities impact more than one product.
Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs
Oracle's August 2026 CSPU fixes 925 CVEs across 943 patches, including 154 critical fixes; Fusion Middleware gets 262 patches.
Oracle released its August 2026 Critical Security Patch Update on August 18, addressing 925 unique CVEs with 943 security updates. 154 issues (16.3%) carry a critical severity rating. Oracle Fusion Middleware received the most patches at 262, accounting for 27.8% of the total. Oracle introduced the monthly CSPU cycle in May 2026 as an interim release between quarterly Critical Patch Updates.
ZDI-26-644: Oracle VirtualBox VMSVGA Race Condition Local Privilege Escalation Vulnerability
ZDI publishes ZDI-26-644 for CVE-2026-60155, a race condition local privilege escalation in Oracle VirtualBox VMSVGA, rated CVSS 7.5.
Zero Day Initiative published advisory ZDI-26-644 describing a race condition in Oracle VirtualBox's VMSVGA component. Local attackers who already execute high-privileged code on the guest system can escalate privileges on affected installations. ZDI rated the issue CVSS 7.5 and assigned CVE-2026-60155.
ZDI-26-635: Oracle Outside In Technology PDF File Parsing Integer Overflow Remote Code Execution Vulnerability
ZDI disclosed CVE-2026-60392, an integer overflow in Oracle Outside In PDF parsing enabling remote code execution, rated CVSS 7.8.
The Zero Day Initiative published advisory ZDI-26-635 describing an integer overflow vulnerability in PDF file parsing within Oracle Outside In Technology. Successful exploitation allows remote code execution but requires user interaction, such as opening a malicious file or visiting a malicious page. ZDI assigned the flaw a CVSS rating of 7.8.
USN-8769-1: phpseclib vulnerability
Ubuntu patches phpseclib non-constant-time padding validation enabling remote padding oracle timing attacks against AES-CBC.
Ubuntu security notice USN-8769-1 addresses a vulnerability in phpseclib where padding validation was not performed in constant time when using AES in CBC mode. A remote attacker could leverage this timing side channel to conduct a padding oracle attack and decrypt sensitive information. Users are advised to update the phpseclib package.