Oracle Patches 800+ Vulnerabilities in September 2026 Security Update

Oracle’s September 2026 Critical Security Patch Update (CSPU) Brings Record Number of Fixes for Over 800 Vulnerabilities

In a significant move to shore up its software ecosystem, Oracle has released 673 new security patches as part of its September 2026 CSPU. These updates address more than 800 vulnerabilities, with over 100 classified as critical-severity flaws and over 240 that can be exploited remotely without authentication.

The patch update affects a wide range of Oracle products, including E-Business Suite, Fusion Middleware, Hyperion, Siebel CRM, Analytics, Communications, Commerce, Supply Chain, Virtualization, PeopleSoft, Database Server, Enterprise Manager, Financial Services Applications, Application Testing Suite, Java SE, Autonomous Health Framework, and Utilities Applications. The largest batch of patches was released for Oracle E-Business Suite, with 159 updates to resolve various security defects.

Fusion Middleware followed closely behind, receiving 153 patches that address 78 unauthenticated, remotely exploitable flaws. Hyperion was also significantly affected, with 102 patches (50 of which can be exploited without authentication) released to fix its vulnerabilities. Other products received substantial numbers of patches as well, including Siebel CRM (63), Analytics (50), Communications (31), Commerce (27), Supply Chain (19), Virtualization (19), and PeopleSoft (16).

One notable aspect of the update is that Oracle Communications received a large number of patches to resolve 125 additional CVEs. This suggests that threat actors have been actively targeting vulnerabilities in this area, making it crucial for users to apply these updates as soon as possible.

Oracle explicitly warns its customers about the risks associated with not applying security patches in a timely manner. The company notes that attackers often exploit unpatched vulnerabilities, and it urges users to remain on actively-supported versions of its software and apply security patches without delay.

While Oracle does not mention any specific instances of these vulnerabilities being exploited in the wild, the sheer number of patches released highlights the importance of keeping software up-to-date. This is especially true for organizations that rely heavily on Oracle’s products, as a single unpatched vulnerability can have severe consequences.

In light of this update, it’s essential for users to review their system configurations and ensure they are applying security patches in a timely manner. This not only helps prevent potential attacks but also demonstrates a proactive approach to cybersecurity.


Source: SecurityWeek — 2026-09-16