Oracle patches 673 updates for 800+ vulnerabilities

Oracle’s September 2026 security update includes 673 fixes for more than 800 vulnerabilities, including over 100 critical flaws and more than 240 remotely exploitable without authentication.

On Tuesday, Oracle released its September 2026 Critical Security Patch Update, delivering 673 fixes that address more than 800 vulnerabilities. The advisory lists 672 unique CVEs across 17 risk matrices and notes additional patches that resolve over 130 further CVEs. More than 100 of the newly addressed defects are rated critical, and the advisory marks more than 240 as remotely exploitable without authentication.

Enterprise applications received the largest share of fixes. Oracle E-Business Suite received 159 patches, 19 of which address vulnerabilities that can be exploited remotely without authentication. Fusion Middleware received 153 patches, including fixes for 78 unauthenticated remote-execution flaws. Hyperion was updated with 102 patches, 50 of which close remotely exploitable defects. Other product families covered in the CSPU include Siebel CRM with 63 patches, Analytics with 50, Communications with 31, Commerce with 27, Supply Chain and Virtualization with 19 each, and PeopleSoft with 16.

The Communications update includes a notable set of fixes: about half of its 31 patches resolve an additional group of more than 125 CVEs. The CSPU also provides fixes for Database Server, Enterprise Manager, Financial Services Applications, Application Testing Suite, Java SE, Autonomous Health Framework, and Utilities Applications.

Oracle reports no evidence that any of the newly patched vulnerabilities are being actively exploited in the wild. The advisory warns that attackers regularly target flaws in Oracle products and recommends prompt patching. “In some instances, it has been reported that attackers have been successful because targeted customers had failed to apply available Oracle patches. Oracle therefore strongly recommends that customers remain on actively-supported versions and apply security patches without delay,” the advisory states.

The September advisory groups fixes by product family and severity and supplies detailed risk matrices for administrators to review. Organizations running affected Oracle software should consult the matrices to identify applicable patches and prioritize updates based on exposure and business impact.

Articles by this author