Oracle September 2026 Security Update: 673 Patches Across 17 Product Families
Oracle released its September 2026 Critical Security Patch Update (CSPU) on September 15 with 673 new security patches across 17 product families. The release covers Oracle Database Server, Fusion Middleware, E-Business Suite, Java SE, Hyperion, Analytics, Communications, Virtualization and other enterprise products.
The patch volume is substantial, with the largest groups concentrated in Oracle E-Business Suite (159 patches) and Oracle Fusion Middleware (153 patches). Oracle's risk matrices identify 19 E-Business Suite patches and 78 Fusion Middleware patches for vulnerabilities that can be remotely exploited over a network without authentication. Hyperion receives 102 patches, including 50 in that remotely exploitable-without-authentication category.
Oracle recommends that customers remain on actively supported releases and apply security patches without delay. The company says it continues to receive reports of exploitation attempts against vulnerabilities for which patches were already available, including cases where attacks succeeded against systems that had not received those fixes.
September 2026 Oracle patch overview
| Product family | New patches | Remotely exploitable without authentication |
|---|---|---|
| Oracle E-Business Suite | 159 | 19 |
| Oracle Fusion Middleware | 153 | 78 |
| Oracle Hyperion | 102 | 50 |
| Oracle Siebel CRM | 63 | 26 |
| Oracle Analytics | 50 | 8 |
| Oracle Communications | 31 | 23 |
| Oracle Commerce | 27 | 16 |
| Oracle Supply Chain | 19 | 5 |
| Oracle Virtualization | 19 | 1 |
| Oracle PeopleSoft | 16 | 4 |
| Oracle Database Server | 11 | 5 |
| Oracle Enterprise Manager | 7 | 5 |
| Oracle Financial Services Applications | 6 | 2 |
| Oracle Application Testing Suite | 3 | 0 |
| Oracle Java SE | 3 | 3 |
| Oracle Autonomous Health Framework | 2 | 1 |
| Oracle Utilities Applications | 2 | 1 |
The table reflects Oracle's September CSPU risk matrices. A single patch can address more than one vulnerability or third-party component issue. Patch counts are therefore most useful as deployment-planning indicators; they are not one-to-one CVE counts.
Fusion Middleware carries the highest immediate exposure
Fusion Middleware deserves early attention because its 153 patches include 78 vulnerabilities that Oracle classifies as remotely exploitable without authentication. Several components also contain maximum-severity CVSS 3.1 issues.
Five Fusion Middleware vulnerabilities carry a CVSS 10.0 base score:
| CVE | Component | CVSS |
|---|---|---|
| CVE-2026-71133 | Oracle Access Manager | 10.0 |
| CVE-2026-83099 | Oracle Forms | 10.0 |
| CVE-2026-83059 | Oracle Internet Directory | 10.0 |
| CVE-2026-83020 | Oracle Platform Security for Java | 10.0 |
| CVE-2026-83021 | Oracle WebLogic Server | 10.0 |
Oracle's matrices classify these five issues as network-accessible, low-complexity vulnerabilities requiring no privileges and no user interaction. That combination makes externally reachable Middleware deployments a high-priority patch group.
Oracle Hyperion Financial Management also includes CVE-2026-87230, another CVSS 10.0 vulnerability that Oracle classifies as remotely exploitable without authentication.
E-Business Suite has the largest patch set
Oracle E-Business Suite receives 159 new security patches, the highest patch count in the September release. Nineteen are listed as remotely exploitable without authentication.
For large EBS environments, patch planning should start with the exact installed product and component versions in Oracle's risk matrix and Patch Availability Documents. Oracle's CSPU pages link each affected product family to the corresponding installation and availability documentation.
This matters for estates with multiple Oracle products because the advisory is a portfolio-level release, while the deployable patch and prerequisite sequence remains product- and version-specific.
Database, Java and virtualization are also in scope
Oracle Database Server receives 11 patches, including five for vulnerabilities categorized as remotely exploitable without authentication. Java SE receives three patches, all three in that category. Oracle Virtualization receives 19 patches, with one listed as remotely exploitable without authentication.
Administrators should inventory the Oracle products actually deployed before using raw severity as the only prioritization signal. Internet exposure, authentication requirements, reachable services, data sensitivity and the role of a component in the identity or application stack materially affect remediation priority.
A practical first pass is:
- Identify externally reachable Oracle Fusion Middleware, E-Business Suite, Hyperion, Database and Communications systems.
- Map each installed product and release to Oracle's September 2026 risk matrix and Patch Availability Document.
- Prioritize unauthenticated network attack paths and CVSS 10.0/9.x issues on exposed systems.
- Confirm prerequisite and cumulative-patch requirements for each product before rollout.
- Patch supported test or staging environments, validate application behavior, then move through production according to service criticality.
- Review systems that have remained behind on earlier Oracle security releases because Oracle's advisory explicitly highlights exploitation of previously patched vulnerabilities.
CSPU is Oracle's newer monthly security cadence
Oracle introduced Critical Security Patch Updates in 2026 to supplement its established quarterly Critical Patch Update cycle. CSPUs provide a smaller, more focused monthly vehicle for high-priority fixes between the larger quarterly releases.
Oracle lists the next security release dates as October 20, November 17 and December 15, 2026, followed by January 19, 2027. October and January are scheduled quarterly CPUs; November and December are CSPUs.
The monthly cadence changes operational planning for Oracle estates. Teams that previously organized remediation around a quarterly window now need a process capable of evaluating consequential Oracle fixes every month while retaining the broader quarterly CPU workflow.
Evidence and scope
Oracle's September advisory is the authoritative source for affected products, risk matrices and patch availability. Independent analysis from Tenable counts 672 unique CVEs across the 673 security updates, including 104 critical-severity patches. SecurityWeek independently reports the same 673-patch total and notes that the release addresses more than 800 vulnerabilities when additional CVEs resolved through patches for other flaws are included.
Those figures describe different units: Oracle's headline figure is 673 new security patches, while CVE and underlying-vulnerability totals can differ because individual updates may address multiple issues. For operational use, Oracle's product-specific risk matrices and Patch Availability Documents provide the deployable requirements behind the aggregate counts.
Bottom line
Oracle's September 2026 CSPU is a broad enterprise patch cycle with the most concentrated exposure in E-Business Suite and Fusion Middleware. The immediate priority is to identify internet-facing and authentication-free attack surfaces, then map installed versions to Oracle's product-specific patch documentation.
Fusion Middleware stands out with 153 patches, 78 remotely exploitable-without-authentication entries and five CVSS 10.0 vulnerabilities. E-Business Suite has the largest patch volume at 159. Organizations running either stack should treat the September CSPU as the current remediation cycle and complete the applicable fixes ahead of the October quarterly CPU.