60
60
30
57
55
35
55
55
42
55
60
60
Oracle Critical Security Patch Update, September 2026 Review
Oracle's September 2026 Critical Patch Update fixes 673 vulnerabilities, including 104 critical, with many remotely exploitable in E-Business Suite and Fusion Middleware.
Oracle released 673 security patches in its September 2026 Critical Patch Update: 104 rated critical, 503 high, and 59 medium. Oracle E-Business Suite received the most patches (159, 24% of total), with 19 exploitable without credentials including CVE-2026-83327, CVE-2026-83452, and CVE-2026-83462 at CVSS 9.8. Fusion Middleware received 153 patches with 78 remotely exploitable without authentication, and 41 patches address third-party open-source component flaws. Qualys published detection QIDs for vulnerable assets.
55
60
60
55
A “highly critical” flaw affects Drupal 7 and 8 core, Drupal security updates expected on March 28th
55
60
30
55
60
60
42
60
60
30
30
60
60
35
55
55
60
60
60
60
60
60
55
60