[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fXvWefEG7xgPq-X8Ds8h952GwGAfWXXqePJgTrDRPDNQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":42},"b337a39a-60b1-446d-872c-b20c145e1518","oracle-patches-673-vulnerabilities-including-104-critical-flaws-in-september-2026-cpu","c2f89199-24d3-470d-8bd7-b1375a522c75","Oracle Patches 673 Vulnerabilities Including 104 Critical Flaws in September 2026 CPU","Oracle's September 2026 Critical Security Patch Update highlights the persistent and massive scale of vulnerability exposure across enterprise software ecosystems, with 673 patches issued in a single cycle — 104 of them critical. Particularly alarming are the unauthenticated exploitable vulnerabilities in Oracle E-Business Suite, which represents a severe risk for organizations that have not applied patches promptly, as attackers can compromise systems without needing valid credentials. The inclusion of third-party and non-Oracle CVEs underscores how complex supply chain dependencies amplify the attack surface of widely deployed platforms. Organizations that delay patching Oracle environments — often due to testing concerns or operational constraints — leave themselves exposed to well-documented, publicly known exploit paths. Timely application of Critical Patch Updates (CPUs) is not optional; it is a foundational security control for any organization running Oracle products.","**Immediate actions:**\n- Apply Oracle's September 2026 CPU patches immediately, prioritizing the 104 critical vulnerabilities and all unauthenticated attack vectors in Oracle E-Business Suite.\n- Conduct an emergency audit to identify all internet-facing or externally accessible Oracle systems that may be exposed to unauthenticated exploits.\n- Isolate unpatched Oracle E-Business Suite instances behind stricter network controls until patches can be applied.\n\n**Long-term improvements:**\n- Establish a formal patch management policy that mandates critical vendor patches (CVSS 9.0+) be applied within 72 hours of release.\n- Maintain a continuously updated software asset inventory that maps all Oracle products and versions deployed across the enterprise.\n- Implement a risk-based patching framework that accounts for third-party and dependency CVEs bundled within vendor update packages.\n\n**Detection measures:**\n- Deploy vulnerability scanning tools configured to detect unpatched Oracle CVEs immediately after each quarterly CPU release.\n- Enable detailed logging and alerting on Oracle E-Business Suite authentication events to detect exploitation attempts against unpatched systems.\n- Subscribe to Oracle Security Alerts and threat intelligence feeds to receive advance warning of actively exploited vulnerabilities before patches are applied.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 7: Continuous Vulnerability Management","CIS Control 2: Inventory and Control of Software Assets","NIST SP 800-40 Rev. 4: Guide to Enterprise Patch Management Planning","NIST SI-2: Flaw Remediation","NIST RA-5: Vulnerability Monitoring and Scanning","NIST CM-8: System Component Inventory","ISO\u002FIEC 27001:2022 Annex A 8.8: Management of Technical Vulnerabilities","ITIL 4: Change Enablement and Release Management Practices","GDPR Article 32: Security of Processing (obligation to apply timely security measures)","PCI DSS Requirement 6.3: Security Vulnerabilities are Identified and Addressed","published","2026-09-16T16:20:55.257411+00:00","2026-09-16T16:20:54.978+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fblog.qualys.com\u002Fvulnerabilities-threat-research\u002F2026\u002F09\u002F16\u002Foracle-critical-security-patch-update-september-2026-review","oracle-critical-security-patch-update-september-2026-review-47142c","Oracle Critical Security Patch Update, September 2026 Review",[30,36],{"id":31,"name":32,"slug":33,"description":34,"color":35},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":37,"name":38,"slug":39,"description":40,"color":41},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[43],{"id":44,"date":45,"edition":46,"title":47,"audio_url":48},"013c6944-8435-44e5-bfd0-1f59a4ef13de","2026-09-17","morning","ThreatNoir Morning Brief — September 17","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-09-17\u002Fthreatnoir-morning-brief-2026-09-17.mp3"]