[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fKpoWRf1_6aNIzoL8-CNXWoXVsq4DxnaLGjglJ4zlItc":3},{"article":4,"iocs":40},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"7a334d32-dbcb-4e28-a5d1-97522e7e6c52","Oracle Patches 800+ Vulnerabilities in September 2026 Security Update","oracle-patches-800-vulnerabilities-in-september-2026-security-update-4967e5","The security updates resolve over 800 vulnerabilities across 17 product families, including over 100 critical-severity flaws. The post Oracle Patches 800+ Vulnerabilities in September 2026 Security Update appeared first on SecurityWeek.","Oracle has released its September 2026 Critical Security Patch Update (CSPU), delivering 673 patches that fix over 800 vulnerabilities across 17 product families. The update includes more than 100 critical-severity flaws and over 240 that are remotely exploitable without authentication. Oracle E-Business Suite received the largest number of patches with 159 fixes.","Oracle releases 673 security patches addressing over 800 vulnerabilities, including critical flaws.","Oracle on Tuesday announced the release of 673 new security patches as part of its September 2026 Critical Security Patch Update (CSPU). The security updates appear to resolve more than 800 vulnerabilities: there are 672 unique CVEs in the 17 risk matrices included in the September 2026 CSPU advisory, but Oracle also notes that more than 130 additional CVEs have been resolved with the patches for other flaws. More than 100 of the newly addressed security defects are critical-severity flaws, and over 240 are remotely exploitable without authentication. Oracle E-Business Suite received 159 security patches, the largest batch of the CSPU. 19 of the vulnerabilities can be exploited remotely without authentication. Fusion Middleware followed closely, receiving 153 patches, including fixes for 78 unauthenticated, remotely exploitable flaws. Hyperion was third, with 102 patches (50 remotely exploitable without authentication). Oracle also rolled out a significant number of patches for Siebel CRM (63), Analytics (50), Communications (31), Commerce (27), Supply Chain (19), Virtualization (19), and PeopleSoft (16).Advertisement. Scroll to continue reading. The Communications update stands out, as half of its patches resolve more than 125 additional CVEs. Other Oracle products that received patches this month include Database Server, Enterprise Manager, Financial Services Applications, Application Testing Suite, Java SE, Autonomous Health Framework, and Utilities Applications. Oracle makes no mention of any of these vulnerabilities being exploited in the wild, but warns users that threat actors are regularly exploiting flaws in its products, urging customers to apply the updates as soon as possible. “In some instances, it has been reported that attackers have been successful because targeted customers had failed to apply available Oracle patches. Oracle therefore strongly recommends that customers remain on actively-supported versions and apply security patches without delay,” Oracle notes. Related: $1 Million Sandbox Challenge Uncovers Linux Kernel Flaws Related: Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases Related: Thai Broadband Provider Hacked via Fortinet Vulnerability Related: Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire 240,000 Hit by Data Breach at Japan’s Digital AgencyApple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix AttackPersonal, Financial Info Exposed in Revolut Data BreachChinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code ExecutionThree JFrog Artifactory Flaws Exploited for Backdoor DeploymentConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like AttacksBlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days Latest News Acronis Patches Exploited Vulnerability in cPanel Backup PluginEnterprises Warned of Attacks Exploiting WSO2 VulnerabilityMicrosoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?“We Think the Security Control Is Working” Is No Longer Good Enough$1 Million Sandbox Challenge Uncovers Linux Kernel FlawsExein Secures $270M at $1.7B Valuation for Physical AI SecurityTexas Utility CenterPoint Energy Confirms Breach After Hacker Leaks DataThai Broadband Provider Hacked via Fortinet Vulnerability Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveGeoff Belknap has joined HubSpot as Chief Trust Officer.Zero Networks has named Yossi Dagan as Chief Financial Officer.Manifold has appointed Joe Sullivan to its Board of Directors.More People On The MoveExpert Insights “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, \"data\" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Foracle-patches-800-vulnerabilities-in-september-2026-security-update\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2025\u002F10\u002FOracle.jpeg","2026-09-16T08:06:33+00:00","2026-09-16T10:00:27.750195+00:00",8,[18,21,24,26,28,30],{"name":19,"type":20},"Oracle","vendor",{"name":22,"type":23},"Oracle E-Business Suite","product",{"name":25,"type":23},"Fusion Middleware",{"name":27,"type":23},"Hyperion",{"name":29,"type":23},"Siebel CRM",{"name":31,"type":23},"Java SE","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":32,"icon":34,"name":35,"slug":36},null,"Vulnerabilities","vulnerabilities",[38],{"category":39},{"id":32,"icon":34,"name":35,"slug":36},[]]