Oracle Critical Security Patch Update, September 2026 Review
Oracle releases September 2026 Critical Security Patch Update with 673 vulnerability fixes.
Summary
Oracle has issued its September 2026 Critical Security Patch Update, addressing a total of 673 vulnerabilities across its product suite. Of these, 104 are rated critical, 503 important, and 59 medium. Oracle E-Business Suite received the largest number of patches with 159, including several critical vulnerabilities exploitable without authentication. The update also includes patches for third-party components and non-Oracle CVEs.
Full text
Oracle released its September edition of Critical Security Patch Update. The update received patches for 673 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products. Out of the 673 security updates published, a total of 104 (15.5%) vulnerabilities are rated critical, 503 are rated as important (74.7%), and 59 are rated as medium. In this Oracle Critical Security Patch Update, Oracle E-Business Suite received the highest number of patches, 159, constituting about 24% of the total patches released. 41 of the 673 (about 6%) security patches in the September Critical Security Patch Update are for non-Oracle CVEs, such as open-source components included in, and exploitable within, Oracle product distributions. This batch of security patches received 13 updates for Oracle Database products. The following is the product-wise distribution: 11 new security updates for Oracle Database Server with a maximum reported CVSS Base Score of 8.8. 2 of these updates apply to client-only deployments of the Oracle Database. 2 new security updates for Oracle Autonomous Health Framework with a maximum reported CVSS Base Score of 7.5. The complete list of Oracle product families and the no of patches issued are listed below: Oracle Product Family No. of Patches Remote Exploit without AuthenticationOracle E-Business Suite 159 19 Oracle Fusion Middleware 153 78 Oracle Hyperion 102 50 Oracle Siebel CRM 63 26 Oracle Analytics 50 8 Oracle Communications 31 23 Oracle Commerce 27 16 Oracle Supply Chain 19 5 Oracle Virtualization 19 1 Oracle PeopleSoft 16 4 Oracle Database Server 11 5 Oracle Enterprise Manager 7 5 Oracle Financial Services Applications 6 2 Oracle Application Testing Suite 3 0 Oracle Java SE 3 3 Oracle Autonomous Health Framework 2 1 Oracle Utilities Applications 2 1 Qualys QID Coverage Qualys has released the following QIDS mentioned in the table: QIDsTitle 388781 Oracle Coherence September 2026 Critical Patch Update (CPUSEP2026) 388780 Oracle Managed Virtualization (VM) VirtualBox September 2026 Critical Patch Update (CSPUSEP2026 Windows) 388779 Oracle Managed Virtualization (VM) VirtualBox September 2026 Critical Patch Update (CSPUSEP2026) 388778 Oracle JDeveloper September 2026 Critical Patch Update (CSPUSEP2026) 388773 Oracle PeopleSoft Enterprise PeopleTools Product Multiple Vulnerabilities (CSPUSEP2026) 87618 Oracle WebLogic Server September 2026 Critical Patch Update (CSPUSEP2026) 20626 Oracle E-Business Suite Security Update (CPUSEP2026) Note: The table will be updated with additional QIDs once released. Notable Oracle Vulnerabilities Patched Oracle E-Business Suite This Critical Security Patch Update for Oracle E-Business Suite received 159 security patches. Out of these, 19 vulnerabilities can be exploited over a network without user credentials. CVE-2026-83327, CVE-2026-83452, and CVE-2026-83462 have a critical severity rating and a CVSS score of 9.8. Oracle Fusion Middleware This Critical Security Patch Update for Oracle Fusion Middleware received 153 security patches. Out of these, 78 vulnerabilities can be exploited over a network without user credentials. A total of 67 CVEs affecting various Oracle Fusion Middleware products have critical severity ratings. Oracle Hyperion This Critical Security Patch Update for Oracle Hyperion received 102 security patches. Out of these, 50 vulnerabilities can be exploited over a network without user credentials. A total of 14 CVEs affecting various Oracle Hyperion products have critical severity ratings. Oracle Siebel CRM This Critical Security Patch Update for Oracle Siebel CRM received 63 security patches. Out of these, 26 vulnerabilities can be exploited over a network without user credentials. CVE-2026-83197, CVE-2026-83196, CVE-2026-83201, CVE-2026-83202, CVE-2026-83229, and CVE-2026-83154 have critical severity ratings. Oracle Analytics This Critical Security Patch Update for Oracle Analytics received 50 security patches. Out of these, 8 vulnerabilities can be exploited over a network without user credentials. CVE-2026-83282, CVE-2026-83269, CVE-2026-83283, and CVE-2026-83268 have critical severity ratings. Related
Indicators of Compromise
- cve — CVE-2026-83327
- cve — CVE-2026-83452
- cve — CVE-2026-83462
- cve — CVE-2026-83197
- cve — CVE-2026-83196
- cve — CVE-2026-83201
- cve — CVE-2026-83202
- cve — CVE-2026-83229
- cve — CVE-2026-83154