Oracle released 673 security patches on 15 September 2026, 247 of them for vulnerabilities that are remotely exploitable without authentication. Six carry the maximum score of 10.0, five of those in Fusion Middleware.
The facts
On 15 September 2026, Oracle published its September Critical Security Patch Update, CSPU (1). The advisory carries 673 security patches across sixteen product families and seventeen risk matrices, the Database Products family being split into two matrices. The document is at revision 1, dated the day of release.
Of those 673 patches, 247 address vulnerabilities that Oracle qualifies as remotely exploitable without authentication, that is 36.7 per cent of the release. Oracle does not publish that total: it is obtained by adding up the opening sentence of each of the seventeen matrices. Scores are assigned with version 3.1 of the Common Vulnerability Scoring System, CVSS (2), following the vendor’s own scoring conventions.
Six vulnerabilities reach the maximum score of 10.0. Five sit in Fusion Middleware, the sixth in Hyperion Financial Management. Two families account for 312 of the 673 patches, that is 46.4 per cent: E-Business Suite with 159 and Fusion Middleware with 153.
The advisory repeats the vendor’s standing warning: Oracle states that it regularly receives reports of attempts to exploit vulnerabilities for which patches already exist, and that some of those attempts succeed because the available patches were not applied. The associated recommendation is to stay on actively supported versions and to apply security patches without delay.
The smaller format Oracle advertises applies to the set of products covered each month, not to the volume of patches. With 673 in September after 943 in August, two consecutive CSPUs exceed the size of an earlier generation quarterly Critical Patch Update. The qualification workload now comes round twelve times a year.
The monthly cadence and what it changes
Oracle changed its release rhythm in 2026. The first CSPU was published on 28 May 2026. Since then, CSPUs are released on the third Tuesday of February, March, May, June, August, September, November and December. The quarterly Critical Patch Updates, CPU (3), remain in January, April, July and October, and remain cumulative: they carry forward the fixes already shipped in previous CSPUs.
15 September 2026 is indeed the third Tuesday of the month. The advisory announces the next four dates: 20 October 2026 for a CPU, 17 November and 15 December 2026 for two CSPUs, 19 January 2027 for a CPU. The third Tuesday rule checks out for each of them.
- Twelve security releases a year instead of four, eight CSPUs and four CPUs.
- The product perimeter shifts from one month to the next: MySQL, Oracle Java SE, Retail, Hospitality, JD Edwards, Primavera and Essbase, all covered in August, are absent from the September advisory, which brings in the Utilities Applications family instead.
- A CSPU left unapplied is not lost: the next quarterly CPU carries it forward. The exposure window lengthens accordingly.
- Advisories are revised after publication. The August 2026 advisory reached revision 4 in seventeen days: two revisions changed affected versions, one of them for Helidon on 27 August, and the last, dated 4 September 2026, changed a product name.
How the 673 patches break down
The table restates, family by family, the count Oracle gives at the head of each risk matrix. The column “Remote without authentication” uses the vendor’s own qualification, meaning exploitation over a network with no user name and no password.
| Product family | Patches | Remote without authentication | Top score |
|---|---|---|---|
| Oracle E-Business Suite | 159 | 19 | 9.8 |
| Oracle Fusion Middleware | 153 | 78 | 10.0 |
| Oracle Hyperion | 102 | 50 | 10.0 |
| Oracle Siebel CRM | 63 | 26 | 9.1 |
| Oracle Analytics | 50 | 8 | 9.9 |
| Oracle Communications | 31 | 23 | 9.8 |
| Oracle Commerce | 27 | 16 | 8.2 |
| Oracle Supply Chain | 19 | 5 | 9.8 |
| Oracle Virtualization | 19 | 1 | 8.6 |
| Oracle PeopleSoft | 16 | 4 | 8.8 |
| Oracle Database Products | 13 | 6 | 8.8 |
| Oracle Enterprise Manager | 7 | 5 | 9.8 |
| Oracle Financial Services Applications | 6 | 2 | 8.0 |
| Oracle Application Testing Suite | 3 | 0 | 9.1 |
| Oracle Java SE | 3 | 3 | 8.1 |
| Oracle Utilities Applications | 2 | 1 | 8.2 |
| Total | 673 | 247 | 10.0 |
The top five families account for 527 patches, that is 78.3 per cent of the release. Unauthenticated network exposure concentrates elsewhere than volume does: Fusion Middleware carries 78, Hyperion 50, Siebel 26 and Communications 23, while E-Business Suite, the largest family by volume, carries only 19.
The Database Products family reads in two parts: eleven patches for Oracle Database Server, five of them remotely exploitable without authentication, and two for Autonomous Health Framework, one of them.
Oracle writes the Oracle Analytics release 26 branch two ways in the same publication: 26.1.0.0.0 in the affected products table of the advisory, 26.01.0.0.0 in the risk matrices and in the CSAF (4) file. Exact string matching will not connect the two forms. The check applies to any inventory fed by literal version lookups.
The six vulnerabilities scored 10.0
All six vulnerabilities, each identified by its own CVE (5), are remotely exploitable without authentication, with a changed scope in CVSS terms, meaning an impact that reaches beyond the vulnerable component. Five carry a high impact on confidentiality, integrity and availability. The sixth, CVE-2026-87230, carries a high impact on confidentiality and integrity, and none on availability.
| CVE | Product | Component | Protocol | Affected versions |
|---|---|---|---|---|
| CVE-2026-71133 | Oracle Access Manager | Authentication Engine | HTTP | 12.2.1.4.0, 14.1.2.1.0 |
| CVE-2026-83099 | Oracle Forms | Forms Services, C/S, Charmode | HTTP | 12.2.1.19.0, 14.1.2.0.0 |
| CVE-2026-83059 | Oracle Internet Directory | OID LDAP Server | LDAP (6) | 12.2.1.4.0, 14.1.2.1.0 |
| CVE-2026-83020 | Oracle Platform Security for Java | Centralized Thirdparty Jars | HTTP | 12.2.1.4.0, 14.1.2.0.0 |
| CVE-2026-83021 | Oracle WebLogic Server | Web Container | HTTP | 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 |
| CVE-2026-87230 | Oracle Hyperion Financial Management | Security | HTTP | 11.2.26.0.0 |
One detail deserves attention on CVE-2026-83021: the WebLogic 15.1.1.0.0 branch is not listed among its affected versions, whereas it is listed for the three Core vulnerabilities scored 9.8, CVE-2026-70748, CVE-2026-70756 and CVE-2026-70757, and for CVE-2026-83038 scored 9.9 on the TopLink integration. The fix perimeter is therefore not uniform across branches of the same product.
Fusion Middleware, the identity layer first in line
With 153 patches, 78 of them requiring no prior authentication, Fusion Middleware is the most exposed family in this release. The concentration is clear on the components that handle authentication and directory services, which are by design the ones published at the front door.
Oracle Access Manager
The Authentication Engine component carries CVE-2026-71133 at 10.0, two vulnerabilities at 9.9, CVE-2026-71163 and CVE-2026-73945, and three at 9.8 exploitable without authentication, CVE-2026-73940, CVE-2026-73947 and CVE-2026-73950. CVE-2026-47065, also at 9.8, comes from the Apache Mina third party component. The versions cited for this product are 12.2.1.4.0, 14.1.2.0.0 and 14.1.2.1.0, with the split varying by vulnerability.
Oracle Internet Directory
The LDAP server carries ten vulnerabilities at 9.8 or above: CVE-2026-83059 at 10.0, four at 9.9, CVE-2026-83055 through CVE-2026-83058, and five at 9.8, CVE-2026-83054, CVE-2026-83060, CVE-2026-83061, CVE-2026-83062 and CVE-2026-83066. The attack protocol is LDAP for most of them, T3 or IIOP (7) for the last.
Oracle WebLogic Server
Beyond CVE-2026-83021 at 10.0 on the web container, three Core vulnerabilities are exploitable without authentication over the WebLogic T3 and IIOP protocols and scored 9.8. They affect all four supported branches, 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Filtering T3 and IIOP at the perimeter remains the most direct exposure reduction for this product, subject to application dependencies.
The rest of the family
- Oracle Forms, in 12.2.1.19.0 and 14.1.2.0.0: CVE-2026-83099 at 10.0 and five vulnerabilities at 9.8 on the same Forms Services component.
- WebCenter Portal, WebCenter Sites and WebCenter Enterprise Capture: several vulnerabilities at 9.9 and 9.8, including CVE-2026-83339 on the Capture Client Bundle, exploitable without authentication.
- Oracle Identity Manager and Identity Manager Connector: CVE-2026-70913 and CVE-2026-83042 at 9.8, CVE-2026-83027 at 9.3 over TLS from an adjacent network.
- Helidon, in 3.0.0-3.2.20 and 4.0.0-4.5.4: thirteen vulnerabilities, five of them denial of service at 7.5 against the web server, the HTTP/2 client and static content delivery, plus CVE-2026-83439 at 8.1 on the IDCS security provider.
- Oracle Coherence, Data Integrator, JDeveloper, Managed File Transfer, Web Services Manager, Middleware Common Libraries and Tools and Service Delivery Platform round out the family, with scores from 1.9 to 9.9.
E-Business Suite, Hyperion, Siebel and Analytics
E-Business Suite, 159 patches
Covered versions are 12.2.3 through 12.2.15, plus version V16 for a few modules including Enterprise Command Center Framework and Contract Lifecycle Management for Public Sector. Nineteen vulnerabilities are exploitable without authentication, three of them scored 9.8: CVE-2026-83327 on Oracle Applications Framework personalisation over SOAP, CVE-2026-83452 on Document Management and Collaboration over HTTP, and CVE-2026-83462 on the MWA Terminal Server of Oracle Mobile Application Server over TCP. The large majority of the rest requires an application account, however lightly privileged, with scores ranging from 5.4 to 8.8.
Oracle notes that E-Business Suite products embed Database and Fusion Middleware components whose vulnerabilities are not listed in this matrix. Applying the CSPU to the underlying components is therefore required, with My Oracle Support, MOS (8), note KA923 specifying which patches apply to which environment.
The context around this product is not neutral. In 2025, E-Business Suite was the target of a mass exfiltration and extortion campaign attributed to the Cl0p group, exploiting CVE-2025-61882, scored 9.8, an unauthenticated remote code execution in the BI Publisher Integration component of Oracle Concurrent Processing. Exploitation began in August 2025, Oracle’s out of band security alert is dated 4 October 2025, the entry in the Known Exploited Vulnerabilities, KEV (9), catalogue of the US agency CISA (10) is dated 6 October 2025, and a PoC circulated publicly within days. That campaign has no connection to the vulnerabilities fixed here, but it sets the level of attention this product receives from extortion groups.
Hyperion, 102 patches
The family holds only two products, Hyperion Financial Management and Hyperion Data Relationship Management, both in version 11.2.26.0.0. It nevertheless carries the second highest exposure ratio of the release: 50 of the 102 vulnerabilities are remotely exploitable without authentication, including CVE-2026-87230 at 10.0. The components named are Security for the first product and Access and security for the second, with no further detail from the vendor.
Siebel CRM, 63 patches
Covered versions run from 17.0 to 26.7, with narrower ranges for some components: 22.3 to 26.7 for Siebel Cloud Manager, 25.12 to 26.7 for Open Integration, 23.6 to 26.7 for Event Publish and Subscribe. The top score is 9.1, reached by six vulnerabilities, four of them unauthenticated, among which CVE-2026-83197 on the Financial Services module and CVE-2026-83154 on the Open UI interface over SOAP.
Analytics, 50 patches
BI Publisher and Business Intelligence Enterprise Edition are covered in 8.2.0.0.0, 12.2.1.4.0 and 26.1.0.0.0. The highest score, 9.9, goes to CVE-2026-83282 on BI Enterprise Edition platform security in 12.2.1.4.0, but it requires an account. Two vulnerabilities at 9.8 are exploitable without authentication: CVE-2026-83269 on BI Publisher and CVE-2026-83283 on BI Enterprise Edition. Of the 50 patches, only 8 concern unauthenticated exposure.
Database, Java SE and VirtualBox
Oracle Database Server
Eleven patches for branches 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. The three highest scores, 8.8, all require a database account holding a specific privilege: Create DB Link for CVE-2026-83348, Create Table for CVE-2026-83160, Execute on DBMS_REDEFINITION for CVE-2026-83271. Five vulnerabilities are exploitable without authentication, including CVE-2026-83351 at 8.1 on the RDBMS core in 23.4.0-23.26.3, and three denial of service issues at 7.5 against the Oracle Net Services listener and Connection Manager. Two vulnerabilities affect client only installations, CVE-2026-83348 and CVE-2026-83156.
Autonomous Health Framework receives two patches, one on OpenSSL scored 7.5, the other on DOMPurify scored 4.6, in 26.2, 26.3.1, 26.5.3 and 26.8. Two further third party CVEs are patched although judged not exploitable in their integration context, with the associated VEX (11) justifications.
Java SE
Three patches, all on the Compiler component and all exploitable remotely without authentication: two at 8.1, CVE-2026-83357 and CVE-2026-83408, and one at 7.0, CVE-2026-83368. The products are GraalVM for JDK 17 in 23.0.13.1, GraalVM for JDK 21 in 23.1.12.1 and GraalVM Enterprise Edition in 21.3.19.1. No Oracle JDK patch this month, whereas the August advisory covered Oracle Java SE from 8u501 to 26.0.2.
VirtualBox
Nineteen patches for version 7.2.16 alone, all on the Core component. Only one vulnerability is remotely exploitable without authentication, CVE-2026-87277 at 7.5, over RDP (12) and with an impact limited to availability. The top score, 8.6, goes to CVE-2026-87273, local, with user interaction and a changed scope. Four vulnerabilities, CVE-2026-87268 through CVE-2026-87271, carry a vendor note restricting them to Windows hosts. They are credited to James Forshaw, who signs five of the nineteen entries in this matrix.
Third party components and transitive fixes
The Communications family illustrates on its own how much dependencies weigh. Of its 31 patches, 28 concern third party components, 24 of them embedded in Unified Assurance alone: Fluentd and PHP at 9.8, Apache HttpClient and DBI at 9.1, then Guzzle, MLflow, jackson-databind, Golang Go, Apache Tomcat, Erlang/OTP, ActiveMQ, RabbitMQ, SimpleSAMLphp, libgcrypt, Dompdf, logback, MySQL Server, MediaWiki, Log4j, Helm, CryptX and Node.js. The remaining three patches are on Oracle code, in the Cloud Native Core SEPP (13) proxy.
Sixteen footnotes under the matrix state that one patch covers others. They cite 124 additional CVEs for this family alone. An inventory that reads only the CVE column of the matrix therefore misses most of the actual coverage.
| Lead patch | Third party component | Additional CVEs covered |
|---|---|---|
| CVE-2026-61109 | MySQL Server | 28 |
| CVE-2026-58520 | MediaWiki | 18 |
| CVE-2026-73508 | Netty | 15 |
| CVE-2026-55952 | Erlang/OTP | 10 |
| CVE-2026-57220 | Pivotal RabbitMQ | 10 |
| CVE-2026-64849 | MLflow | 7 |
| CVE-2026-54518 | jackson-databind | 6 |
| CVE-2026-67355 | Guzzle | 6 |
| CVE-2026-73194 | DBI | 6 |
| CVE-2026-59943 | Dompdf | 5 |
The pattern goes beyond that family. In PeopleSoft, the patch for CVE-2026-7598 on libssh2 also covers CVE-2023-48795, known as Terrapin, and CVE-2023-6918. In Financial Services Applications, the Log4j patch for CVE-2026-34480 covers four more, including CVE-2025-68161. That same CVE appears in its own right in the Enterprise Manager matrix, scored 4.8 on the Diagnostic Kit: a 2025 CVE still being worked through product by product.
Oracle also publishes the third party CVEs it judges not exploitable in the integration context, with their VEX justification, for instance vulnerable_code_not_in_execute_path or vulnerable_code_cannot_be_controlled_by_adversary. Those entries are not counted in the 673 patches but can raise alerts in software composition scanners, and are worth quoting as they stand in audit responses.
The published scores are Oracle’s, computed under its own conventions for applying CVSS 3.1. They can differ from the NVD score or from the upstream vendor’s score for the same CVE. No prioritisation decision should rest on the score alone, without accounting for the real exposure of the component concerned.
Source qualification
Every version number, score and identifier was read from the advisory page as rendered in a browser, then cross-checked against the CSAF file Oracle publishes. No value was taken from a plain text conversion of the page, where superscript footnote markers attach themselves to the digits that precede them.
| Item | Status | Comment |
|---|---|---|
| Total of 673 patches and the family breakdown | corroborated | Headline count and the sum of the seventeen matrices agree, addition recomputed |
| 247 vulnerabilities exploitable without authentication | single source | Total not published by Oracle, obtained by adding the opening sentences of the seventeen matrices |
| Scores, components, protocols and versions | corroborated | Rendered advisory page and CSAF file, read independently |
| Monthly cadence and announced calendar | corroborated | Oracle security blog, Security Fixing Policies page and the August advisory, which announced the 15 September date |
| Volume of the August 2026 advisory, 943 patches | corroborated | Read from the August advisory at revision 4 |
| Two spellings of the Oracle Analytics version | corroborated | 26.1.0.0.0 in the affected products table, 26.01.0.0.0 in the CSAF |
| 2025 Cl0p campaign against E-Business Suite | corroborated | Mandiant findings relayed by several publications, Oracle out of band alert, KEV catalogue entry |
| Counts by score other than 10.0 | discarded | Not recomputed exhaustively across the seventeen matrices, therefore not published here |
| Values read from a text conversion of the advisory | discarded | Known superscript footnote artefact, which silently alters version numbers |
Assessment
The analysis covers revision 1 of the advisory, accessed on 16 September 2026. It does not review all 673 entries one by one: the Fusion Middleware, E-Business Suite, Hyperion, Siebel and Analytics matrices were read in full, the others sampled on the highest scores and on the rows marked as exploitable without authentication. The absence of reported exploitation is an observation at a point in time, not a forecast. Later revisions of the advisory may change the affected versions, as happened with the August one.
What to do
This week
- Inventory exposed instances of Access Manager, Internet Directory, Identity Manager, WebLogic Server, Forms and WebCenter, and take the six vulnerabilities scored 10.0 first.
- Check whether the WebLogic T3 and IIOP ports are reachable from untrusted networks, and the same for the Internet Directory LDAP service.
- For E-Business Suite, apply the patches to the underlying Database and Fusion Middleware components, following MOS note KA923, not to the application layer alone.
- For Hyperion, check the installed version against 11.2.26.0.0 and the network reachability of both products concerned.
- For workstations, plan the VirtualBox upgrade beyond 7.2.16.
This month
- Confirm that the May, June and August 2026 CSPUs were actually applied. If not, the 20 October 2026 CPU will carry them forward cumulatively, at the cost of a heavier qualification cycle.
- Put the third Tuesday of the month into the change advisory board calendar, distinguishing CPU from CSPU, and prepare test windows ahead of the release rather than on announcement.
- Carry the sixteen transitive patch footnotes of the Communications family into the component inventory, otherwise 124 CVEs will keep showing as unaddressed.
- Watch for revisions of the September advisory: the August one went through four revisions in seventeen days, two of them correcting affected versions.
A closing remark on how to read these advisories. The score says nothing about exposure: a vulnerability scored 8.8 that requires a database account on an internal server does not call for the same deadline as one scored 7.5 on a directory published at the front door. The column that orders the work is not the score, it is the pair of protocol and exploitation without authentication, crossed with an inventory of the instances that are actually reachable.
Glossary
- CSPU (1): Critical Security Patch Update, Oracle’s monthly security release, targeted at a subset of products, introduced on 28 May 2026.
- CVSS (2): Common Vulnerability Scoring System, the vulnerability scoring system. Oracle applies version 3.1 under its own conventions.
- CPU (3): Critical Patch Update, Oracle’s quarterly cumulative security release, in January, April, July and October. Not to be confused with the central processing unit.
- CSAF (4): Common Security Advisory Framework, a machine readable advisory format Oracle publishes alongside the web page.
- CVE (5): Common Vulnerabilities and Exposures, the unique identifier assigned to a publicly known vulnerability.
- LDAP (6): Lightweight Directory Access Protocol, the protocol used to query and modify a directory.
- IIOP (7): Internet Inter-ORB Protocol, a protocol for communication between distributed objects, used by WebLogic alongside the proprietary T3 protocol.
- MOS (8): My Oracle Support, Oracle’s customer support portal, where patch availability documents are published.
- KEV (9): Known Exploited Vulnerabilities, the catalogue of vulnerabilities with confirmed exploitation, maintained by CISA.
- CISA (10): Cybersecurity and Infrastructure Security Agency, the US cybersecurity and infrastructure security agency.
- VEX (11): Vulnerability Exploitability eXchange, a declaration format stating whether a component vulnerability is exploitable in the context of the product that embeds it.
- RDP (12): Remote Desktop Protocol, a remote desktop access protocol, implemented by VirtualBox for access to virtual machines.
- SEPP (13): Security Edge Protection Proxy, the security function at the edge of 5G mobile networks, which protects exchanges between operators.
Sources
- Oracle, Critical Security Patch Update Advisory – September 2026, revision 1 of 15 September 2026, accessed 16 September 2026. oracle.com
- Oracle, CSAF JSON version of the risk matrices for the September 2026 advisory. oracle.com
- Oracle, English text version of the risk matrices, referenced by the advisory. oracle.com
- Oracle, Critical Security Patch Update Advisory – August 2026, revision 4 of 4 September 2026, for the 943 patch count and the previous month’s product perimeter. oracle.com
- Oracle, Security Fixing Policies, for the CSPU calendar and the cumulative nature of CPUs. oracle.com
- Oracle, security blog, announcement of monthly CSPUs from 28 May 2026. blogs.oracle.com
- Help Net Security, Cl0p extortion campaign against Oracle E-Business Suite and CVE-2025-61882, 6 October 2025. helpnetsecurity.com
- VulnCheck, analysis of CVE-2025-61882 exploitation and the KEV catalogue entry. vulncheck.com
Marked TLP:CLEAR, PAP:CLEAR. Unlimited disclosure, no restriction on use.
The analysis presented here reflects the author’s own views and rests on the public sources listed above.


