ZeroHour
Story · 2 sources · 2 articlesfirst updated ()

Oracle's September 2026 Critical Patch Update Ships 673 Patches Covering 800+ CVEs, Including 100+ Critical and 240+ Remotely Exploitable Flaws

highAdvisoryimportance 58CVE-2026-21962
What's new: First merged summary for this story — no prior baseline. Cyber Security News reconciles the headline '800+ vulnerabilities' figure as an effective total (673 patches / 672 unique CVEs plus 130+ bundled fixes) rather than a count of discrete patches. Report 2 adds the CISA 72-hour remediation order for CVE-2026-21962 (CVSS 10.0), Hyperion's unauthenticated split, the Communications product family,…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Oracle's September 2026 Critical Security Patch Update delivers 673 patches resolving 672 unique CVEs across 17 risk matrices, with 130+ additional CVEs fixed via bundled updates for an effective total above 800; more than 100 flaws are critical and over 240…

Oracle's September 2026 Critical Security Patch Update contains 673 new patches resolving 672 unique CVEs across 17 risk matrices (described by one source as 17 product families), plus 130+ additional CVEs addressed through bundled third-party fixes — an effective remediation total exceeding 800, the figure used in SecurityWeek's headline. More than 100 flaws are rated critical and over 240 are remotely exploitable without authentication. Oracle E-Business Suite received the largest batch with 159 patches (19 exploitable without authentication), followed by Fusion Middleware with 153 (78 remotely exploitable without authentication) and Hyperion with 102 (roughly half unauthenticated, per Cyber Security News). Other patched families include Siebel, Analytics, Communications, Database Server, Java SE, Virtualization, and PeopleSoft. Oracle reports no known exploitation of these specific flaws but warns that attackers routinely target unpatched Oracle products, citing CISA's earlier 72-hour remediation order for actively exploited CVE-2026-21962 (CVSS 10.0). Defenders are advised to prioritize internet-exposed Fusion Middleware, E-Business Suite, and Hyperion deployments.

  • 673 new security patches in the September 2026 CPU, resolving 672 unique CVEs across 17 risk matrices/product families
  • 130+ additional CVEs resolved via bundled fixes, pushing the effective total past 800 (basis for the '800+ vulnerabilities' headline)
  • More than 100 flaws rated critical severity; over 240 remotely exploitable without authentication
  • Oracle E-Business Suite: 159 patches, 19 without authentication — the largest batch
  • Oracle Fusion Middleware: 153 patches, 78 remotely exploitable without authentication
  • Oracle Hyperion: 102 patches, roughly half unauthenticated (per Cyber Security News)
  • Also patched: Siebel, Analytics, Communications, Database Server, Java SE, Virtualization, PeopleSoft
  • No exploitation of these specific flaws reported; Oracle cites CISA's earlier 72-hour remediation order for actively exploited CVE-2026-21962 (CVSS 10.0) as evidence attackers target unpatched Oracle products

Coverage timeline

  1. · 9h ago
    SecurityWeek· 55
    Oracle Patches 800+ Vulnerabilities in September 2026 Security Update

    Oracle's September 2026 Critical Patch Update fixes 800+ vulnerabilities, including over 100 critical flaws and 240+ remotely exploitable without authentication.

  2. · 4h ago
    Cyber Security News· 58
    Oracle Critical Security Update – 673 Vulnerabilities Patched Across Product Families

    Oracle's September 2026 Critical Patch Update ships 673 patches across 17 product families, including 100+ critical and 240+ remotely exploitable flaws.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-21962
Unauthenticated Access Control Bypass in Oracle HTTP Server and WebLogic Proxy Plug-in

CVE-2026-21962 is an improper access control flaw (CWE-284) in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in (components: the plug-in for Apache HTTP Server and the plug-in for IIS), part of Oracle Fusion Middleware. An unauthenticated attacker with network access via HTTP can trivially exploit it, and the scope-change designation means a successful attack can significantly impact additional products beyond the plug-in itself. The attacker gains unauthorized access to critical data (potentially all accessible data) as well as the ability to create, delete, or modify critical data, reflected in the maximum CVSS 10.0 score with high confidentiality and integrity impacts and no availability impact. Organizations running the affected versions - 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0 for Oracle HTTP Server and the Apache plug-in, and 12.2.1.4.0 only for the IIS plug-in - especially those with internet-facing Apache/IIS/OHS front ends proxying WebLogic applications, are exposed. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-24, and EPSS assigns a 42% probability of exploitation within 30 days, though no public proof-of-concept is known.

Do: Apply the fixes from Oracle's January 2026 quarterly update (advisory AV26-042) or later for Oracle HTTP Server and the WebLogic Server Proxy Plug-in on all affected versions - 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0 (IIS plug-in affected at 12.2.1.4.0 only). Prioritize internet-facing OHS, Apache and IIS front ends per CISA BOD 26-04 and the KEV required actions, and where patching is delayed, restrict HTTP access to trusted networks and review logs for signs of unauthorized data access or modification.

10.042% KEV
  • Oracle HTTP Server (Oracle Fusion Middleware) 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0
  • Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0
  • Oracle WebLogic Server Proxy Plug-in for IIS 12.2.1.4.0
large~10,000-100,000 internet-exposed Oracle HTTP Server / WebLogic proxy front ends