Oracle Patches 800+ Vulnerabilities in September 2026 Security Update

Oracle’s massive September 2026 security update patches over 800 vulnerabilities across its vast array of products, with a significant number of critical-severity flaws and remotely exploitable weaknesses that threaten to compromise sensitive data. The tech giant’s latest Critical Security Patch Update (CSPU) brings a much-needed respite for Oracle customers, who can breathe a collective sigh of relief now that these long-standing security defects have been addressed.

Oracle’s CSPU advisory lists 672 unique CVEs, along with over 130 additional vulnerabilities resolved by the patches. The sheer scale of this patch update is staggering, and it underscores the importance of prioritizing timely software updates to prevent exploitation by threat actors. More than 100 of these newly patched vulnerabilities are classified as critical-severity flaws, while an astonishing 240 can be exploited remotely without authentication.

The largest batch of patches was reserved for Oracle E-Business Suite, with a whopping 159 security fixes applied across its various components. Fusion Middleware trailed closely behind, receiving 153 patches that included fixes for 78 unauthenticated, remotely exploitable vulnerabilities. Hyperion also received significant attention, with 102 patches addressing issues including 50 remotely exploitable flaws without authentication.

Other Oracle products, such as Siebel CRM, Analytics, Communications, Commerce, Supply Chain, Virtualization, and PeopleSoft, all received substantial patch updates. The Communications update stood out for its unusually high number of resolved CVEs – a staggering 125 additional vulnerabilities were addressed by the patches. While no mention was made of these vulnerabilities being exploited in the wild, Oracle’s warning to customers is clear: threat actors are actively exploiting flaws in its products, and timely application of security updates is crucial.

The tech giant’s call to action couldn’t be more urgent. “In some instances, it has been reported that attackers have been successful because targeted customers had failed to apply available Oracle patches,” the company notes. With a stark reminder that failing to stay on top of software updates can leave even the most robust security posture vulnerable, Oracle is urging customers to remain on actively-supported versions and apply these patches without delay.

For users who rely on Oracle’s products, this patch update should be treated as an emergency – applying these patches immediately will significantly reduce the risk of exploitation by threat actors. It’s a timely reminder that cybersecurity isn’t just a concern for IT teams; it demands individual vigilance and awareness to stay ahead of emerging threats. By staying informed about vulnerabilities and prioritizing software updates, users can minimize their exposure to potential attacks.


Source: SecurityWeek — 2026-09-16