Oracle September 2026 Security Patch Tuesday

Oracle September 2026 Security Patch Tuesday


673 Security Patches Across the Enterprise

Quick Reference

Release Date: 15 September 2026
Release: Oracle September 2026 Critical Security Patch Update (CSPU)
Security Patches: 673
Highest CVSS: 10.0
Major Product Areas: Oracle E-Business Suite, Fusion Middleware, WebLogic Server, Hyperion, Siebel CRM, Communications, Database, Java, Enterprise Manager and more
Next Oracle Security Release: 20 October 2026 — Critical Patch Update (CPU)

Executive Summary

Oracle’s September 2026 Critical Security Patch Update delivers 673 new security patches across its enterprise product portfolio. Oracle describes CSPUs as targeted, high-priority security releases that complement its quarterly Critical Patch Updates.

The September release is notable for several vulnerabilities that are remotely exploitable without authentication, including multiple CVSS 10.0 vulnerabilities affecting Oracle Fusion Middleware components such as WebLogic Server, Oracle Access Manager, Oracle Forms, Oracle Internet Directory and Oracle Platform Security for Java.

The largest patch volumes include 159 patches for Oracle E-Business Suite and 153 patches for Oracle Fusion Middleware. Oracle identifies 19 E-Business Suite vulnerabilities and 78 Fusion Middleware vulnerabilities as remotely exploitable without authentication.

The exposure extends well beyond Oracle Database. The release spans application platforms, middleware, identity, communications, management, analytics, financial applications, Java and other enterprise technologies.

For security teams, the important question is therefore not simply how many patches Oracle released.

It is:

Which of these vulnerabilities map to reachable assets in our environment, and which of those assets expose an unauthenticated attack path?

The September CSPU should consequently be treated as an asset-level exposure exercise: identify affected products and versions, map the CVEs to actual infrastructure, determine network exposure, patch the affected components and verify remediation.

673 patches is the headline.

Unauthenticated remote attack paths are the signal.

Asset-level validation is the action.

673 Patches Is Only the Starting Point

Oracle’s September CSPU covers a broad enterprise technology ecosystem.

The affected products include:

  • Oracle E-Business Suite
  • Oracle Fusion Middleware
  • Oracle WebLogic Server
  • Oracle Hyperion
  • Oracle Siebel CRM
  • Oracle Communications
  • Oracle Analytics
  • Oracle Database
  • Oracle Enterprise Manager
  • Oracle Java SE
  • Oracle Financial Services Applications
  • Oracle PeopleSoft
  • Oracle Supply Chain
  • Oracle Utilities Applications
  • Oracle Virtualization
  • Oracle Commerce
  • Oracle Application Testing Suite
  • Oracle Autonomous Health Framework

The breadth of the release reinforces one important point:

Oracle patch management cannot be reduced to database patching.

The Oracle attack surface is an interconnected enterprise ecosystem.

A vulnerability in middleware can affect multiple applications.

A vulnerability in an identity component can affect authentication infrastructure.

A vulnerability in a management platform can expose administrative capabilities.

A vulnerability in an Internet-facing application can provide an attacker with an initial foothold.

The product name is only the beginning of the investigation.

The CVEs That Stand Out

The September release contains several vulnerabilities that deserve individual attention because of their combination of remote exploitability, lack of authentication requirements, CVSS severity and potential impact.

CVE-2026-83021 — Oracle WebLogic Server

CVSS: 10.0

This vulnerability affects the Web Container component of Oracle WebLogic Server.

Oracle identifies it as remotely exploitable through HTTP without authentication.

The attack characteristics are:

Network accessible.

Low attack complexity.

No privileges required.

No user interaction required.

Affected versions include:

12.2.1.4.0

14.1.1.0.0

14.1.2.0.0

Oracle’s risk matrix describes successful exploitation as capable of resulting in takeover of Oracle WebLogic Server, with the vulnerability carrying changed scope and high confidentiality, integrity and availability impacts.

For organizations running WebLogic, the immediate investigation should be:

Where are the affected WebLogic versions deployed?

Which instances are reachable from untrusted networks?

Which applications depend on those instances?

Are any instances directly exposed to the Internet?

This is the type of vulnerability where the CVE becomes meaningful only after it is mapped to an actual attack surface.

CVE-2026-83020 — Oracle Platform Security for Java

CVSS: 10.0

This vulnerability affects the Centralized Thirdparty Jars component of Oracle Platform Security for Java.

Oracle identifies an unauthenticated attacker with network access via HTTP as the attack scenario.

Affected versions include:

12.2.1.4.0

14.1.2.0.0

The vulnerability requires no privileges and no user interaction, with high confidentiality, integrity and availability impacts. Successful exploitation can result in takeover of the affected product.

CVE-2026-83059 — Oracle Internet Directory

CVSS: 10.0

This vulnerability affects the OID LDAP Server component of Oracle Internet Directory.

The attack path is different from the HTTP-based vulnerabilities above.

The affected protocol is LDAP.

Oracle identifies the vulnerability as remotely exploitable without authentication, with no privileges and no user interaction required.

Affected versions include:

12.2.1.4.0

14.1.2.1.0

Successful exploitation can result in takeover of Oracle Internet Directory, with high confidentiality, integrity and availability impacts.

For identity infrastructure, this deserves particular attention because directory services can sit at the center of authentication and authorization relationships.

CVE-2026-83099 — Oracle Forms

CVSS: 10.0

This vulnerability affects Forms Services, C/S and Charmode within Oracle Forms.

Oracle identifies an unauthenticated attacker with network access via HTTP as the attack scenario.

Affected versions include:

12.2.1.19.0

14.1.2.0.0

The vulnerability requires no privileges and no user interaction, and successful exploitation can result in takeover of Oracle Forms.

CVE-2026-71133 — Oracle Access Manager

CVSS: 10.0

This vulnerability affects the Authentication Engine in Oracle Access Manager.

Oracle identifies it as remotely exploitable without authentication through HTTP.

Affected versions include:

12.2.1.4.0

14.1.2.1.0

The vulnerability has a changed scope and high confidentiality, integrity and availability impacts. No privileges or user interaction are required.

This is another example where the affected component is particularly important because it sits within the identity and authentication layer.

CVSS 9.8: The Next Layer of Concern

The September release is not only about CVSS 10.0 vulnerabilities.

Several vulnerabilities reach CVSS 9.8 while retaining an unauthenticated remote attack path.

CVE-2026-83327 — Oracle E-Business Suite

CVSS: 9.8

This vulnerability affects Oracle Applications Framework — Personalization within Oracle E-Business Suite.

Affected versions are:

12.2.3–12.2.15

Oracle identifies an unauthenticated attacker with network access via SOAP as the attack scenario.

No privileges are required.

No user interaction is required.

Successful exploitation can result in takeover of Oracle Applications Framework.

This vulnerability becomes even more significant when viewed against the overall E-Business Suite exposure.

Oracle is addressing 159 new security patches for E-Business Suite in this CSPU, with 19 vulnerabilities remotely exploitable without authentication.

CVE-2026-83452 — Oracle E-Business Suite

CVSS: 9.8

This vulnerability affects Oracle Document Management and Collaboration.

The affected versions are 12.2.3–12.2.15.

Oracle identifies an unauthenticated attacker with network access via HTTP as the attack scenario, with no privileges or user interaction required.

Successful exploitation can result in takeover of the affected component.

This is an important reminder that E-Business Suite remediation cannot focus on one application component in isolation.

CVE-2026-44024 — Oracle Communications Unified Assurance

CVSS: 9.8

This vulnerability affects the Core — Fluentd component of Oracle Communications Unified Assurance.

Affected versions are:

6.1.1–7.0.0

Oracle describes it as easily exploitable by an unauthenticated attacker with network access via HTTP.

No privileges or user interaction are required.

Successful exploitation can result in takeover of Oracle Communications Unified Assurance.

The patch also addresses:

CVE-2026-44025

CVE-2026-44160

CVE-2026-44161

This makes the vulnerability particularly relevant for organizations running Unified Assurance components on reachable networks.

CVE-2026-41635 — Oracle Enterprise Manager

CVSS: 9.8

This vulnerability affects the Agent Next Gen — Apache Mina component of Oracle Enterprise Manager Base Platform.

Affected versions include:

13.5

24.1

Oracle identifies an unauthenticated attacker with network access via HTTP as the attack scenario.

No privileges or user interaction are required.

Successful exploitation can result in takeover of Oracle Enterprise Manager Base Platform.

The patch also addresses CVE-2026-41409 and CVE-2026-42779.

Management infrastructure therefore deserves the same exposure assessment as business-facing infrastructure.

CVE-2026-83355 — Oracle Enterprise Manager for Fusion Middleware

CVSS: 9.8

This vulnerability affects the Metrics component of Oracle Enterprise Manager for Fusion Middleware.

Affected versions include:

13.5

24.1

Oracle identifies an unauthenticated attacker with network access via HTTP as the attack scenario.

Successful exploitation can result in takeover of Oracle Enterprise Manager for Fusion Middleware.

Oracle Database: CVE-2026-83351

Oracle Database receives 11 new security patches in this CSPU, of which 5 may be remotely exploitable without authentication.

One of the notable vulnerabilities is:

CVE-2026-83351

CVSS: 8.1

The vulnerability affects the RDBMS component of Oracle Database Server.

Affected versions:

23.4.0–23.26.3

Oracle describes the vulnerability as difficult to exploit by an unauthenticated attacker with network access via Oracle Net.

No privileges are required.

No user interaction is required.

Successful exploitation can result in takeover of the RDBMS.

This is an important distinction.

An Oracle Database vulnerability does not automatically mean that every database is equally exposed.

The attack path depends heavily on how Oracle Net is configured and what network paths can reach the database service.

Security teams should therefore validate:

Oracle Database version

Oracle Net exposure

Network segmentation

Firewall controls

Untrusted network reachability

Database criticality

The September release also contains other Oracle Database vulnerabilities, including CVE-2026-83348, which carries CVSS 8.8 and requires the attacker to have the Create DB Link privilege, and CVE-2026-83272, which carries CVSS 8.5 and requires Create Index privilege.

Oracle E-Business Suite: 159 Patches

The E-Business Suite numbers deserve their own examination.

Oracle is addressing 159 new security patches for Oracle E-Business Suite.

Of these, 19 are remotely exploitable without authentication.

The CVEs above demonstrate why the number alone is not enough.

CVE-2026-83327 provides an unauthenticated SOAP attack path against Oracle Applications Framework.

CVE-2026-83452 provides an unauthenticated HTTP attack path against Document Management and Collaboration.

Security teams should therefore map the E-Business Suite patch set against:

Application versions

External interfaces

SOAP endpoints

HTTP endpoints

Supporting Oracle Database versions

Supporting Fusion Middleware versions

Oracle specifically notes that E-Business Suite deployments can inherit exposure from the Oracle Database and Fusion Middleware versions used underneath them. Oracle recommends applying the September security updates to those supporting components as applicable.

Fusion Middleware: 153 Patches

Oracle Fusion Middleware receives 153 new security patches, with 78 remotely exploitable without authentication.

This is one of the most important sections of the September release because several of the highest-severity vulnerabilities sit within this product family.

The CVSS 10.0 vulnerabilities include:

CVE-2026-71133 — Oracle Access Manager

CVE-2026-83099 — Oracle Forms

CVE-2026-83059 — Oracle Internet Directory

CVE-2026-83020 — Oracle Platform Security for Java

CVE-2026-83021 — Oracle WebLogic Server

This concentration of critical vulnerabilities in the middleware layer reinforces the importance of dependency mapping.

A vulnerable middleware component may not be an isolated application.

It may be supporting several business services.

Why CVSS Alone Is Not Enough

The September release demonstrates why CVSS should be treated as a severity indicator rather than a complete risk model.

Consider two vulnerabilities.

One may have a CVSS 10.0 score but exist only on an isolated internal system.

Another may have a CVSS 9.8 score and sit on an externally reachable production service.

The numerical difference alone does not tell the entire story.

The practical analysis needs to combine:

Severity

Exploitability

Authentication requirements

Network exposure

Asset criticality

Business dependency

Attack-path availability

That produces a more meaningful remediation picture.

The Difference Between a CVE and an Exposure

A CVE exists in a vulnerability database.

An exposure exists in your environment.

They are not the same thing.

Consider the chain:

CVE

Affected Product

Affected Version

Actual Asset

Network Exposure

Authentication Requirement

Business Criticality

Attack Path

Remediation Priority

Breaking that chain at any point can change the actual risk.

That is why vulnerability scanners, CMDBs, application inventories and external attack-surface data need to work together.

What Should Security Teams Do?

The first step is simple:

Find the Oracle assets.

Do not limit the search to Oracle Database.

Look across the entire Oracle technology estate.

Next:

Validate versions.

A product name without a version is insufficient for reliable vulnerability assessment.

Then:

Map the CVEs to assets.

A vulnerability in the Oracle advisory is not automatically an exploitable condition in every deployment.

Then:

Determine exposure.

Is the system Internet-facing?

Is it accessible from an untrusted network?

Does exploitation require authentication?

Does exploitation require privileges?

Is user interaction required?

Which protocol is involved?

Finally:

Validate remediation.

Installing the patch is not the end of the process.

The remediation cycle should be:

Discover → Validate → Prioritize → Patch → Verify → Rescan → Close

Don’t Wait for the Next Quarterly CPU

Oracle’s security release model makes another important point.

The September release is a CSPU, designed as a targeted security update that complements Oracle’s quarterly CPUs.

Oracle’s published schedule identifies the next releases as:

20 October 2026 — CPU

17 November 2026 — CSPU

15 December 2026 — CSPU

19 January 2027 — CPU

This means Oracle security maintenance needs to become a recurring operational process rather than a quarterly event.

The Oracle Patch Tuesday Mindset

For organizations accustomed to Microsoft’s Patch Tuesday, Oracle’s third-Tuesday security cadence provides a similar operational rhythm.

A mature monthly cycle can look like this:

Release Day

Oracle publishes the security update.

Day 1

Security teams identify critical CVEs and correlate them against the asset inventory.

Day 1–2

Internet-facing and unauthenticated attack paths are investigated.

Day 2–3

Patch testing and deployment begin for affected production systems.

Following Days

Patches are deployed across remaining affected assets.

After Deployment

Vulnerability rescanning and patch verification are performed.

Closure

Evidence is retained and exceptions are formally documented.

The objective is not simply to achieve patch compliance.

The objective is to remove exploitable attack paths.

The Bigger Picture

The headline says:

673 security patches.

But the September Oracle release tells a deeper story.

The attack surface is distributed across:

Applications.

Middleware.

Identity.

Management platforms.

Communications systems.

Databases.

Enterprise services.

The most significant vulnerabilities are not necessarily the ones with the largest numbers attached to them.

They are the vulnerabilities that combine:

Remote reachability

No authentication

Low attack complexity

No user interaction

High-impact outcomes

That combination appears repeatedly in the September risk matrices.

Final Takeaway

Oracle’s September 2026 CSPU delivers 673 new security patches across the Oracle enterprise ecosystem.

Among them are multiple CVSS 10.0 vulnerabilities affecting Oracle Fusion Middleware components, including WebLogic Server, Access Manager, Forms, Internet Directory and Platform Security for Java.

The release also contains high-severity unauthenticated vulnerabilities in E-Business Suite, Communications Unified Assurance and Enterprise Manager, while Oracle Database includes CVE-2026-83351, a CVSS 8.1 vulnerability that can allow an unauthenticated attacker with Oracle Net access to take over the RDBMS.

But the most important number is not 673.

It is the number of those vulnerabilities that map to your actual assets.

That is where vulnerability management becomes security.

Because the real question is never:

“How many vulnerabilities did Oracle release?”

The real question is:

“How many of these vulnerabilities can an attacker reach in our environment — and how quickly can we remove that exposure?”

The September Oracle CSPU is therefore more than another patch notification.

It is an opportunity to reassess the Oracle attack surface.

Patch the vulnerability.

Validate the exposure.

Verify the fix.

Close the attack path.

Official References

Oracle September 2026 Critical Security Patch Update Advisory

Oracle September 2026 Risk Matrices — Detailed CVE Information

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.