Skip to main content

Oracle Patches 800+ Vulnerabilities in September 2026 Security Update

0
Critical
Vulnerability
Published: 09/16/2026 (09/16/2026, 08:06:33 UTC)
Source: SecurityWeek

Description

Oracle released its September 2026 Critical Security Patch Update addressing over 800 vulnerabilities across 17 product families, including more than 100 critical-severity flaws. Many of these vulnerabilities are remotely exploitable without authentication. The update includes significant patches for Oracle E-Business Suite, Fusion Middleware, Hyperion, and other major Oracle products. Oracle warns that attackers regularly exploit vulnerabilities in its products and urges customers to apply patches promptly. No active exploitation of these specific vulnerabilities has been reported at this time.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/16/2026, 08:16:43 UTC

Technical Analysis

Oracle's September 2026 Critical Security Patch Update (CSPU) includes 673 new security patches resolving over 800 vulnerabilities, with more than 100 classified as critical severity. Among these, over 240 vulnerabilities are remotely exploitable without authentication. The patches cover 17 Oracle product families, with the largest number applied to Oracle E-Business Suite (159 patches), Fusion Middleware (153 patches), and Hyperion (102 patches). Other products patched include Siebel CRM, Analytics, Communications, Commerce, Supply Chain, Virtualization, PeopleSoft, Database Server, Enterprise Manager, Financial Services Applications, Application Testing Suite, Java SE, Autonomous Health Framework, and Utilities Applications. Oracle emphasizes the importance of applying these patches promptly to mitigate risks, noting that some attackers have succeeded due to unpatched systems. There is no current evidence of exploitation in the wild for these specific vulnerabilities.

Potential Impact

The vulnerabilities addressed include over 100 critical-severity flaws, many of which are remotely exploitable without authentication, potentially allowing attackers to compromise affected systems. The broad range of affected Oracle products means that multiple enterprise environments could be at risk if patches are not applied. However, no active exploitation of these vulnerabilities has been reported so far. Failure to apply these patches could expose organizations to increased risk of compromise.

Mitigation Recommendations

Oracle strongly recommends that customers remain on actively supported versions and apply the September 2026 Critical Security Patch Update without delay. Applying these patches promptly is the primary mitigation to address the vulnerabilities. No additional mitigation guidance or temporary workarounds are provided or indicated by Oracle at this time.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.95,"severitySource":"stated","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/oracle-patches-800-vulnerabilities-in-september-2026-security-update/","fetched":true,"fetchedAt":"2026-09-16T08:16:36.468Z","wordCount":976}

Threat ID: 6aaa506455bf5e2cf5378b52

Added to database: 09/16/2026, 08:16:36 UTC

Last enriched: 09/16/2026, 08:16:43 UTC

Last updated: 09/17/2026, 03:22:28 UTC

Views: 15

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses