Oracle Releases September 2026 Security Patch: 673 Fixes for Over 800 Vulnerabilities

September 16, 2026
Oracle Releases September 2026 Security Patch: 673 Fixes for Over 800 Vulnerabilities
  • Oracle released its September 2026 Critical Security Patch Update (CSPU), patching more than 800 vulnerabilities across multiple Oracle products with 673 new security patches.

  • The CSPU advisory documents 672 unique CVEs across 17 risk matrices, with Oracle noting more than 130 additional CVEs resolved through patches for other flaws.

  • In a pattern of substantial patching, Oracle also issued a CSPU in August addressing nearly 1,000 vulnerabilities across various products.

  • Several flaws are unauthenticated and remotely exploitable, notably in Fusion Middleware, E-Business Suite, and Hyperion, prompting priority patching for internet-facing deployments.

  • Oracle warns that attackers have targeted environments lacking patches, underscoring the risk of delayed remediation and urging timely patching.

  • While no exploitation in the wild is confirmed, Oracle notes threat actors frequently target its products and urges customers to apply patches promptly.

  • Oracle emphasizes staying on actively-supported versions and applying patches without delay due to past attacker success when systems remained unpatched.

  • Administrators should review the CSPU patch list, identify affected products in use, and prioritize patches for critical-risk vulnerabilities to reduce attack opportunities.

  • Administrators are advised to consult the official CSPU overview page for detailed vulnerability and patch information and to apply updates promptly to reduce attack surface.

  • The current CSPU cycle signals a blurring of lines between monthly CSPUs and quarterly CPUs, reflecting an accelerated patch cadence in 2026.

  • Multiple products carry CVSS-rated critical risks, including Oracle WebLogic Server, Identity Manager, BI Publisher, Siebel apps, Oracle Agile PLM, and several Enterprise Manager components.

  • Oracle plans to continue quarterly patching, with the next CPU scheduled for October 2026 as part of the standard cadence.

Summary based on 3 sources


Get a daily email with more Tech stories

More Stories