
673 Security Patches Across the Enterprise
Quick Reference
Release Date: 15 September 2026
Release: Oracle September 2026 Critical Security Patch Update (CSPU)
Security Patches: 673
Highest CVSS: 10.0
Major Product Areas: Oracle E-Business Suite, Fusion Middleware, WebLogic Server, Hyperion, Siebel CRM, Communications, Database, Java, Enterprise Manager and more
Next Oracle Security Release: 20 October 2026 — Critical Patch Update (CPU)
Executive Summary
Oracle’s September 2026 Critical Security Patch Update delivers 673 new security patches across its enterprise product portfolio. Oracle describes CSPUs as targeted, high-priority security releases that complement its quarterly Critical Patch Updates.
The September release is notable for several vulnerabilities that are remotely exploitable without authentication, including multiple CVSS 10.0 vulnerabilities affecting Oracle Fusion Middleware components such as WebLogic Server, Oracle Access Manager, Oracle Forms, Oracle Internet Directory and Oracle Platform Security for Java.
The largest patch volumes include 159 patches for Oracle E-Business Suite and 153 patches for Oracle Fusion Middleware. Oracle identifies 19 E-Business Suite vulnerabilities and 78 Fusion Middleware vulnerabilities as remotely exploitable without authentication.
The exposure extends well beyond Oracle Database. The release spans application platforms, middleware, identity, communications, management, analytics, financial applications, Java and other enterprise technologies.
For security teams, the important question is therefore not simply how many patches Oracle released.
It is:
Which of these vulnerabilities map to reachable assets in our environment, and which of those assets expose an unauthenticated attack path?
The September CSPU should consequently be treated as an asset-level exposure exercise: identify affected products and versions, map the CVEs to actual infrastructure, determine network exposure, patch the affected components and verify remediation.
673 patches is the headline.
Unauthenticated remote attack paths are the signal.
Asset-level validation is the action.
673 Patches Is Only the Starting Point
Oracle’s September CSPU covers a broad enterprise technology ecosystem.
The affected products include:
- Oracle E-Business Suite
- Oracle Fusion Middleware
- Oracle WebLogic Server
- Oracle Hyperion
- Oracle Siebel CRM
- Oracle Communications
- Oracle Analytics
- Oracle Database
- Oracle Enterprise Manager
- Oracle Java SE
- Oracle Financial Services Applications
- Oracle PeopleSoft
- Oracle Supply Chain
- Oracle Utilities Applications
- Oracle Virtualization
- Oracle Commerce
- Oracle Application Testing Suite
- Oracle Autonomous Health Framework
The breadth of the release reinforces one important point:
Oracle patch management cannot be reduced to database patching.
The Oracle attack surface is an interconnected enterprise ecosystem.
A vulnerability in middleware can affect multiple applications.
A vulnerability in an identity component can affect authentication infrastructure.
A vulnerability in a management platform can expose administrative capabilities.
A vulnerability in an Internet-facing application can provide an attacker with an initial foothold.
The product name is only the beginning of the investigation.
The CVEs That Stand Out
The September release contains several vulnerabilities that deserve individual attention because of their combination of remote exploitability, lack of authentication requirements, CVSS severity and potential impact.
CVE-2026-83021 — Oracle WebLogic Server
CVSS: 10.0
This vulnerability affects the Web Container component of Oracle WebLogic Server.
Oracle identifies it as remotely exploitable through HTTP without authentication.
The attack characteristics are:
Network accessible.
Low attack complexity.
No privileges required.
No user interaction required.
Affected versions include:
12.2.1.4.0
14.1.1.0.0
14.1.2.0.0
Oracle’s risk matrix describes successful exploitation as capable of resulting in takeover of Oracle WebLogic Server, with the vulnerability carrying changed scope and high confidentiality, integrity and availability impacts.
For organizations running WebLogic, the immediate investigation should be:
Where are the affected WebLogic versions deployed?
Which instances are reachable from untrusted networks?
Which applications depend on those instances?
Are any instances directly exposed to the Internet?
This is the type of vulnerability where the CVE becomes meaningful only after it is mapped to an actual attack surface.
CVE-2026-83020 — Oracle Platform Security for Java
CVSS: 10.0
This vulnerability affects the Centralized Thirdparty Jars component of Oracle Platform Security for Java.
Oracle identifies an unauthenticated attacker with network access via HTTP as the attack scenario.
Affected versions include:
12.2.1.4.0
14.1.2.0.0
The vulnerability requires no privileges and no user interaction, with high confidentiality, integrity and availability impacts. Successful exploitation can result in takeover of the affected product.
CVE-2026-83059 — Oracle Internet Directory
CVSS: 10.0
This vulnerability affects the OID LDAP Server component of Oracle Internet Directory.
The attack path is different from the HTTP-based vulnerabilities above.
The affected protocol is LDAP.
Oracle identifies the vulnerability as remotely exploitable without authentication, with no privileges and no user interaction required.
Affected versions include:
12.2.1.4.0
14.1.2.1.0
Successful exploitation can result in takeover of Oracle Internet Directory, with high confidentiality, integrity and availability impacts.
For identity infrastructure, this deserves particular attention because directory services can sit at the center of authentication and authorization relationships.
CVE-2026-83099 — Oracle Forms
CVSS: 10.0
This vulnerability affects Forms Services, C/S and Charmode within Oracle Forms.
Oracle identifies an unauthenticated attacker with network access via HTTP as the attack scenario.
Affected versions include:
12.2.1.19.0
14.1.2.0.0
The vulnerability requires no privileges and no user interaction, and successful exploitation can result in takeover of Oracle Forms.
CVE-2026-71133 — Oracle Access Manager
CVSS: 10.0
This vulnerability affects the Authentication Engine in Oracle Access Manager.
Oracle identifies it as remotely exploitable without authentication through HTTP.
Affected versions include:
12.2.1.4.0
14.1.2.1.0
The vulnerability has a changed scope and high confidentiality, integrity and availability impacts. No privileges or user interaction are required.
This is another example where the affected component is particularly important because it sits within the identity and authentication layer.
CVSS 9.8: The Next Layer of Concern
The September release is not only about CVSS 10.0 vulnerabilities.
Several vulnerabilities reach CVSS 9.8 while retaining an unauthenticated remote attack path.
CVE-2026-83327 — Oracle E-Business Suite
CVSS: 9.8
This vulnerability affects Oracle Applications Framework — Personalization within Oracle E-Business Suite.
Affected versions are:
12.2.3–12.2.15
Oracle identifies an unauthenticated attacker with network access via SOAP as the attack scenario.
No privileges are required.
No user interaction is required.
Successful exploitation can result in takeover of Oracle Applications Framework.
This vulnerability becomes even more significant when viewed against the overall E-Business Suite exposure.
Oracle is addressing 159 new security patches for E-Business Suite in this CSPU, with 19 vulnerabilities remotely exploitable without authentication.
CVE-2026-83452 — Oracle E-Business Suite
CVSS: 9.8
This vulnerability affects Oracle Document Management and Collaboration.
The affected versions are 12.2.3–12.2.15.
Oracle identifies an unauthenticated attacker with network access via HTTP as the attack scenario, with no privileges or user interaction required.
Successful exploitation can result in takeover of the affected component.
This is an important reminder that E-Business Suite remediation cannot focus on one application component in isolation.
CVE-2026-44024 — Oracle Communications Unified Assurance
CVSS: 9.8
This vulnerability affects the Core — Fluentd component of Oracle Communications Unified Assurance.
Affected versions are:
6.1.1–7.0.0
Oracle describes it as easily exploitable by an unauthenticated attacker with network access via HTTP.
No privileges or user interaction are required.
Successful exploitation can result in takeover of Oracle Communications Unified Assurance.
The patch also addresses:
CVE-2026-44025
CVE-2026-44160
CVE-2026-44161
This makes the vulnerability particularly relevant for organizations running Unified Assurance components on reachable networks.
CVE-2026-41635 — Oracle Enterprise Manager
CVSS: 9.8
This vulnerability affects the Agent Next Gen — Apache Mina component of Oracle Enterprise Manager Base Platform.
Affected versions include:
13.5
24.1
Oracle identifies an unauthenticated attacker with network access via HTTP as the attack scenario.
No privileges or user interaction are required.
Successful exploitation can result in takeover of Oracle Enterprise Manager Base Platform.
The patch also addresses CVE-2026-41409 and CVE-2026-42779.
Management infrastructure therefore deserves the same exposure assessment as business-facing infrastructure.
CVE-2026-83355 — Oracle Enterprise Manager for Fusion Middleware
CVSS: 9.8
This vulnerability affects the Metrics component of Oracle Enterprise Manager for Fusion Middleware.
Affected versions include:
13.5
24.1
Oracle identifies an unauthenticated attacker with network access via HTTP as the attack scenario.
Successful exploitation can result in takeover of Oracle Enterprise Manager for Fusion Middleware.
Oracle Database: CVE-2026-83351
Oracle Database receives 11 new security patches in this CSPU, of which 5 may be remotely exploitable without authentication.
One of the notable vulnerabilities is:
CVE-2026-83351
CVSS: 8.1
The vulnerability affects the RDBMS component of Oracle Database Server.
Affected versions:
23.4.0–23.26.3
Oracle describes the vulnerability as difficult to exploit by an unauthenticated attacker with network access via Oracle Net.
No privileges are required.
No user interaction is required.
Successful exploitation can result in takeover of the RDBMS.
This is an important distinction.
An Oracle Database vulnerability does not automatically mean that every database is equally exposed.
The attack path depends heavily on how Oracle Net is configured and what network paths can reach the database service.
Security teams should therefore validate:
Oracle Database version
Oracle Net exposure
Network segmentation
Firewall controls
Untrusted network reachability
Database criticality
The September release also contains other Oracle Database vulnerabilities, including CVE-2026-83348, which carries CVSS 8.8 and requires the attacker to have the Create DB Link privilege, and CVE-2026-83272, which carries CVSS 8.5 and requires Create Index privilege.
Oracle E-Business Suite: 159 Patches
The E-Business Suite numbers deserve their own examination.
Oracle is addressing 159 new security patches for Oracle E-Business Suite.
Of these, 19 are remotely exploitable without authentication.
The CVEs above demonstrate why the number alone is not enough.
CVE-2026-83327 provides an unauthenticated SOAP attack path against Oracle Applications Framework.
CVE-2026-83452 provides an unauthenticated HTTP attack path against Document Management and Collaboration.
Security teams should therefore map the E-Business Suite patch set against:
Application versions
External interfaces
SOAP endpoints
HTTP endpoints
Supporting Oracle Database versions
Supporting Fusion Middleware versions
Oracle specifically notes that E-Business Suite deployments can inherit exposure from the Oracle Database and Fusion Middleware versions used underneath them. Oracle recommends applying the September security updates to those supporting components as applicable.
Fusion Middleware: 153 Patches
Oracle Fusion Middleware receives 153 new security patches, with 78 remotely exploitable without authentication.
This is one of the most important sections of the September release because several of the highest-severity vulnerabilities sit within this product family.
The CVSS 10.0 vulnerabilities include:
CVE-2026-71133 — Oracle Access Manager
CVE-2026-83099 — Oracle Forms
CVE-2026-83059 — Oracle Internet Directory
CVE-2026-83020 — Oracle Platform Security for Java
CVE-2026-83021 — Oracle WebLogic Server
This concentration of critical vulnerabilities in the middleware layer reinforces the importance of dependency mapping.
A vulnerable middleware component may not be an isolated application.
It may be supporting several business services.
Why CVSS Alone Is Not Enough
The September release demonstrates why CVSS should be treated as a severity indicator rather than a complete risk model.
Consider two vulnerabilities.
One may have a CVSS 10.0 score but exist only on an isolated internal system.
Another may have a CVSS 9.8 score and sit on an externally reachable production service.
The numerical difference alone does not tell the entire story.
The practical analysis needs to combine:
Severity
Exploitability
Authentication requirements
Network exposure
Asset criticality
Business dependency
Attack-path availability
That produces a more meaningful remediation picture.
The Difference Between a CVE and an Exposure
A CVE exists in a vulnerability database.
An exposure exists in your environment.
They are not the same thing.
Consider the chain:
CVE
↓
Affected Product
↓
Affected Version
↓
Actual Asset
↓
Network Exposure
↓
Authentication Requirement
↓
Business Criticality
↓
Attack Path
↓
Remediation Priority
Breaking that chain at any point can change the actual risk.
That is why vulnerability scanners, CMDBs, application inventories and external attack-surface data need to work together.
What Should Security Teams Do?
The first step is simple:
Find the Oracle assets.
Do not limit the search to Oracle Database.
Look across the entire Oracle technology estate.
Next:
Validate versions.
A product name without a version is insufficient for reliable vulnerability assessment.
Then:
Map the CVEs to assets.
A vulnerability in the Oracle advisory is not automatically an exploitable condition in every deployment.
Then:
Determine exposure.
Is the system Internet-facing?
Is it accessible from an untrusted network?
Does exploitation require authentication?
Does exploitation require privileges?
Is user interaction required?
Which protocol is involved?
Finally:
Validate remediation.
Installing the patch is not the end of the process.
The remediation cycle should be:
Discover → Validate → Prioritize → Patch → Verify → Rescan → Close
Don’t Wait for the Next Quarterly CPU
Oracle’s security release model makes another important point.
The September release is a CSPU, designed as a targeted security update that complements Oracle’s quarterly CPUs.
Oracle’s published schedule identifies the next releases as:
20 October 2026 — CPU
17 November 2026 — CSPU
15 December 2026 — CSPU
19 January 2027 — CPU
This means Oracle security maintenance needs to become a recurring operational process rather than a quarterly event.
The Oracle Patch Tuesday Mindset
For organizations accustomed to Microsoft’s Patch Tuesday, Oracle’s third-Tuesday security cadence provides a similar operational rhythm.
A mature monthly cycle can look like this:
Release Day
Oracle publishes the security update.
Day 1
Security teams identify critical CVEs and correlate them against the asset inventory.
Day 1–2
Internet-facing and unauthenticated attack paths are investigated.
Day 2–3
Patch testing and deployment begin for affected production systems.
Following Days
Patches are deployed across remaining affected assets.
After Deployment
Vulnerability rescanning and patch verification are performed.
Closure
Evidence is retained and exceptions are formally documented.
The objective is not simply to achieve patch compliance.
The objective is to remove exploitable attack paths.
The Bigger Picture
The headline says:
673 security patches.
But the September Oracle release tells a deeper story.
The attack surface is distributed across:
Applications.
Middleware.
Identity.
Management platforms.
Communications systems.
Databases.
Enterprise services.
The most significant vulnerabilities are not necessarily the ones with the largest numbers attached to them.
They are the vulnerabilities that combine:
Remote reachability
No authentication
Low attack complexity
No user interaction
High-impact outcomes
That combination appears repeatedly in the September risk matrices.
Final Takeaway
Oracle’s September 2026 CSPU delivers 673 new security patches across the Oracle enterprise ecosystem.
Among them are multiple CVSS 10.0 vulnerabilities affecting Oracle Fusion Middleware components, including WebLogic Server, Access Manager, Forms, Internet Directory and Platform Security for Java.
The release also contains high-severity unauthenticated vulnerabilities in E-Business Suite, Communications Unified Assurance and Enterprise Manager, while Oracle Database includes CVE-2026-83351, a CVSS 8.1 vulnerability that can allow an unauthenticated attacker with Oracle Net access to take over the RDBMS.
But the most important number is not 673.
It is the number of those vulnerabilities that map to your actual assets.
That is where vulnerability management becomes security.
Because the real question is never:
“How many vulnerabilities did Oracle release?”
The real question is:
“How many of these vulnerabilities can an attacker reach in our environment — and how quickly can we remove that exposure?”
The September Oracle CSPU is therefore more than another patch notification.
It is an opportunity to reassess the Oracle attack surface.
Patch the vulnerability.
Validate the exposure.
Verify the fix.
Close the attack path.
Official References
Oracle September 2026 Critical Security Patch Update Advisory
Oracle September 2026 Risk Matrices — Detailed CVE Information


