Skip to content

CSPU advisory

www.oracle.com September 16, 2026

A Critical Security Patch Update (CSPU) provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption. Critical Security Patch Updates complement Oracle’s existing quarterly cumulative Critical Patch Updates (CPUs). These patches address vulnerabilities in Oracle code and in third party components included in Oracle products. Prior Critical Patch Update and Critical Security Patch Update advisories should be reviewed for information regarding earlier published security patches. Refer to Critical Patch Updates, Critical Security Patch Updates, Security Alerts and Bulletins for information Oracle Security advisories.

Oracle continues to periodically receive reports of attempts to maliciously exploit vulnerabilities for which Oracle has already released security patches. In some instances, it has been reported that attackers have been successful because targeted customers had failed to apply available Oracle patches. Oracle therefore strongly recommends that customers remain on actively-supported versions and apply security patches without delay.

This Critical Security Patch Update contains 673 new security patches across the product families listed below. Please note that a My Oracle Support (MOS) note summarizing the content of this Critical Security Patch Update and other Oracle Software Security Assurance activities is located at September 2026 Critical Security Patch Update: Executive Summary and Analysis .

Affected Products and Patch Information

Security vulnerabilities addressed by this Critical Security Patch Update affect the products listed below.

Please click on the links in the Patch Availability Document column below to access the documentation for patch availability information and installation instructions.

Risk matrices list only security vulnerabilities that are newly addressed by the patches associated with this advisory. Risk matrices for security patches can be found in Critical Patch Update advisories, Critical Security Patch Update advisories and Alerts . An English text version of the risk matrices provided in this document is here .

Several vulnerabilities addressed in this Critical Security Patch Update affect multiple products. Each vulnerability is identified by a CVE ID . A vulnerability that affects multiple products will appear with the same CVE ID in all risk matrices.

Security vulnerabilities are scored using CVSS version 3.1 (see Oracle CVSS Scoring for an explanation of how Oracle applies CVSS version 3.1).

Oracle conducts an analysis of each security vulnerability addressed by a Critical Security Patch Update. Oracle does not disclose detailed information this security analysis to customers, but the resulting Risk Matrix and associated documentation provide information conditions required to exploit the vulnerability and the potential impact of a successful exploit. Oracle provides this information so that customers may conduct their own risk analysis based on the particulars of their product usage. For more information, see Oracle vulnerability disclosure policies .

Third party component vulnerabilities that are deemed not exploitable in the context of their inclusion in an Oracle product are listed, with VEX justifications, below the respective Oracle product's risk matrix.

The protocol in the risk matrix implies that all of its secure variants are affected as well. For example, if HTTP is listed as an affected protocol, it implies that HTTPS is also affected. The secure variant of a protocol is listed in the risk matrix only if it is the only variant affected.

Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Critical Security Patch Update security patches as soon as possible . Until you apply the Critical Security Patch Update patches, it may be possible to reduce the risk of successful attack by blocking network protocols required by an attack. For attacks that require certain privileges or access to certain packages, removing the privileges or the ability to access the packages from users that do not need the privileges may help reduce the risk of successful attack. Both approaches may break application functionality, so Oracle strongly recommends that customers test changes on non-production systems. Neither approach should be considered a long-term solution as neither corrects the underlying problem.

Skipped Security Patch Updates

Oracle strongly recommends that customers apply security patches as soon as possible. For customers that have skipped one or more security patches and are concerned products that do not have security patches announced in this Critical Security Patch Update, please review Critical Patch Update and Critical Security Patch Update advisories to determine appropriate actions.

Critical Security Patch Update Supported Products and Versions

Patches released through the Critical Security Patch Update program are provided only for product versions that are covered under the Premier Support or Extended Support phases of the Lifetime Support Policy . Oracle recommends that customers plan product upgrades to ensure that patches released through the Critical Security Patch Update program are available for the versions they are currently running.

Product releases that are not under Premier Support or Extended Support are not tested for the presence of vulnerabilities addressed by this Critical Security Patch Update. However, it is likely that earlier versions of affected releases are also affected by these vulnerabilities. As a result, Oracle recommends that customers upgrade to supported versions.

The following people or organizations reported security vulnerabilities addressed by this Critical Security Patch Update to Oracle:

Diego Palacios: CVE-2026-87273

James Forshaw: CVE-2026-87268, CVE-2026-87269, CVE-2026-87270, CVE-2026-87271, CVE-2026-87272

Khalilov M (3ntr0py1337): CVE-2026-87275

Kirishiki Yudai: CVE-2026-87279

Myeonghun Pak and Seongmin Kim of Team SaturnX: CVE-2026-87267

Nathan Tsai: CVE-2026-87274

Nebula Security: CVE-2026-87280, CVE-2026-87281, CVE-2026-87282, CVE-2026-87283, CVE-2026-87284, CVE-2026-87285

Nhat Anh Vu: CVE-2026-87289

Polina Demura: CVE-2026-70755

Samet Akilli: CVE-2026-83354

Tristan Madani of Talence Security: CVE-2026-87276

Wei Ming Tan: CVE-2026-87277, CVE-2026-87278

Upcoming Security Release Dates

Security patches are released on the third Tuesday of each month. The four dates are:

20 October 2026 (CPU)

17 November 2026 (CSPU)

15 December 2026 (CSPU)

19 January 2027 (CPU)

Oracle Critical Patch Updates, Critical Security Patch Updates, Security Alerts and Bulletins

Oracle Critical Patch Updates, Critical Security Patch Updates and Security Alerts - Frequently Asked Questions

Risk Matrix Definitions

Use of Common Vulnerability Scoring System (CVSS) by Oracle

English text version of the risk matrices

CSAF JSON version of the risk matrices

Map of CVE to Advisory/Alert

Oracle Lifetime Support Policy

JEP 290 Reference Blocklist Filter

Oracle Database Products Risk Matrices

This Critical Security Patch Update contains 13 new security patches for Oracle Database Products divided as follows:

11 new security patches for Oracle Database Products

2 new security patches for Oracle Autonomous Health Framework

Oracle Database Server Risk Matrix

This Critical Security Patch Update contains 11 new security patches for Oracle Database Products. 5 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. 2 of these patches are applicable to client-only installations, i.e., installations that do not have the Oracle Database Server installed. The English text form of this Risk Matrix can be found here.

Oracle Database Server Client-Only Installations

The following Oracle Database Server vulnerabilities included in this Critical Security Patch Update affect client-only installations: CVE-2026-83348 and CVE-2026-83156.

Oracle Autonomous Health Framework Risk Matrix

This Critical Security Patch Update contains 2 new security patches , plus additional third party patches noted below, for Oracle Autonomous Health Framework. 1 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.

Additional patches included for the following non-exploitable CVEs for this Oracle product family:

Oracle Autonomous Health Framework AHFCOMMON: CVE-2026-61308 [VEX Justification: vulnerable_code_not_in_execute_path]. CLISDK (pip): CVE-2026-13346 [VEX Justification: vulnerable_code_cannot_be_controlled_by_adversary].

AHFCOMMON: CVE-2026-61308 [VEX Justification: vulnerable_code_not_in_execute_path].

CLISDK (pip): CVE-2026-13346 [VEX Justification: vulnerable_code_cannot_be_controlled_by_adversary].

Oracle Application Testing Suite Risk Matrix

This Critical Security Patch Update contains 3 new security patches for Oracle Application Testing Suite. None of these vulnerabilities may be remotely exploitable without authentication, i.e., none may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.

Oracle Commerce Risk Matrix

This Critical Security Patch Update contains 27 new security patches for Oracle Commerce. 16 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.

Oracle Communications Risk Matrix

This Critical Security Patch Update contains 31 new security patches for Oracle Communications. 23 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.

Additional CVEs addressed are:

The patch for CVE-2026-34477 also addresses CVE-2026-34478 and CVE-2026-34480.

The patch for CVE-2026-48998 also addresses CVE-2026-49214, CVE-2026-55766, and CVE-2026-59882.

The patch for CVE-2026-61109 also addresses CVE-2026-46936, CVE-2026-47012, CVE-2026-47023, CVE-2026-47052, CVE-2026-47064, CVE-2026-60145, CVE-2026-60163, CVE-2026-60177, CVE-2026-60178, CVE-2026-60182, CVE-2026-60183, CVE-2026-60184, CVE-2026-60185, CVE-2026-60186, CVE-2026-60187, CVE-2026-60188, CVE-2026-60189, CVE-2026-60190, CVE-2026-60191, CVE-2026-60315, CVE-2026-60316, CVE-2026-60331, CVE-2026-60332, CVE-2026-60585, CVE-2026-60747, CVE-2026-61081, CVE-2026-61094, and CVE-2026-61096.

The patch for CVE-2026-41239 also addresses CVE-2026-0540, CVE-2026-41238, and CVE-2026-41240.

The patch for CVE-2026-55952 also addresses CVE-2026-48855, CVE-2026-48856, CVE-2026-48858, CVE-2026-48860, CVE-2026-49759, CVE-2026-49760, CVE-2026-53422, CVE-2026-54886, CVE-2026-54887, and CVE-2026-55950.

The patch for CVE-2026-73194 also addresses CVE-2026-10879, CVE-2026-14380, CVE-2026-14739, CVE-2026-14740, CVE-2026-73193, and CVE-2026-9698.

The patch for CVE-2026-64849 also addresses CVE-2026-10803, CVE-2026-13484, CVE-2026-3198, CVE-2026-4035, CVE-2026-69146, CVE-2026-69148, and CVE-2026-8147.

The patch for CVE-2026-73508 also addresses CVE-2026-44249, CVE-2026-45416, CVE-2026-45673, CVE-2026-45674, CVE-2026-47691, CVE-2026-50010, CVE-2026-50020, CVE-2026-55831, CVE-2026-55833, CVE-2026-56745, CVE-2026-56746, CVE-2026-59898, CVE-2026-59899, CVE-2026-59901, and CVE-2026-59921.

The patch for CVE-2026-59943 also addresses CVE-2026-55554, CVE-2026-55555, CVE-2026-56722, CVE-2026-59941, and CVE-2026-59942.

The patch for CVE-2026-67355 also addresses CVE-2026-55568, CVE-2026-55767, CVE-2026-59883, CVE-2026-67339, CVE-2026-67353, and CVE-2026-67354.

The patch for CVE-2026-41989 also addresses CVE-2026-41990.

The patch for CVE-2026-57220 also addresses CVE-2026-57211, CVE-2026-57212, CVE-2026-57213, CVE-2026-57214, CVE-2026-57215, CVE-2026-57216, CVE-2026-57217, CVE-2026-57218, CVE-2026-57219, and CVE-2026-57221.

The patch for CVE-2026-58520 also addresses CVE-2026-13706, CVE-2026-13707, CVE-2026-14358, CVE-2026-14363, CVE-2026-58024, CVE-2026-58025, CVE-2026-58026, CVE-2026-58027, CVE-2026-58028, CVE-2026-58029, CVE-2026-58030, CVE-2026-58032, CVE-2026-58033, CVE-2026-58037, CVE-2026-58038, CVE-2026-58517, CVE-2026-58521, and CVE-2026-8857.

The patch for CVE-2026-39822 also addresses CVE-2026-42505.

The patch for CVE-2026-54518 also addresses CVE-2026-54512, CVE-2026-54513, CVE-2026-54514, CVE-2026-54515, CVE-2026-54516, and CVE-2026-54517.

The patch for CVE-2026-44024 also addresses CVE-2026-44025, CVE-2026-44160, and CVE-2026-44161.

Oracle E-Business Suite Risk Matrix

This Critical Security Patch Update contains 159 new security patches for Oracle E-Business Suite. 19 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.

Oracle E-Business Suite products include Oracle Database and Oracle Fusion Middleware components that are affected by the vulnerabilities listed in the Oracle Database and Oracle Fusion Middleware sections. The exposure of Oracle E-Business Suite products is dependent on the Oracle Database and Oracle Fusion Middleware versions being used. Oracle Database and Oracle Fusion Middleware security updates are not listed in the Oracle E-Business Suite risk matrix. However, since vulnerabilities affecting Oracle Database and Oracle Fusion Middleware versions may affect Oracle E-Business Suite products, Oracle recommends that customers apply the September 2026 Critical Security Patch Update to the Oracle Database and Oracle Fusion Middleware components of Oracle E-Business Suite. For information on what patches need to be applied to your environments, refer to Oracle E-Business Suite Release 12 Critical Security Patch Update Knowledge Document (September 2026), My Oracle Support Note KA923 .

Oracle Enterprise Manager Risk Matrix

This Critical Security Patch Update contains 7 new security patches for Oracle Enterprise Manager. 5 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. None of these patches are applicable to client-only installations, i.e., installations that do not have Oracle Enterprise Manager installed. The English text form of this Risk Matrix can be found here.

Oracle Enterprise Manager products include Oracle Database and Oracle Fusion Middleware components that are affected by the vulnerabilities listed in the Oracle Database and Oracle Fusion Middleware sections. The exposure of Oracle Enterprise Manager products is dependent on the Oracle Database and Oracle Fusion Middleware versions being used. Oracle Database and Oracle Fusion Middleware security updates are not listed in the Oracle Enterprise Manager risk matrix. However, since vulnerabilities affecting Oracle Database and Oracle Fusion Middleware versions may affect Oracle Enterprise Manager products, Oracle recommends that customers apply the September 2026 Critical Security Patch Update to the Oracle Database and Oracle Fusion Middleware components of Enterprise Manager. For information on what patches need to be applied to your environments, refer to Critical Security Patch Update September 2026 Patch Availability Document for Oracle Products, My Oracle Support Note CPU350 .

Additional CVEs addressed are:

The patch for CVE-2026-41635 also addresses CVE-2026-41409 and CVE-2026-42779.

Oracle Financial Services Applications Risk Matrix

This Critical Security Patch Update contains 6 new security patches for Oracle Financial Services Applications. 2 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.

Additional CVEs addressed are:

The patch for CVE-2026-34480 also addresses CVE-2025-68161, CVE-2026-34477, CVE-2026-34478, and CVE-2026-34479.

Oracle Fusion Middleware Risk Matrix

This Critical Security Patch Update contains 153 new security patches for Oracle Fusion Middleware. 78 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.

To get the full list of current and previously released Critical Security Patch Update and Critical Patch Update patches for Oracle Fusion Middleware products, refer to My Oracle Support Doc ID KA1182 .

Oracle Analytics Risk Matrix

This Critical Security Patch Update contains 50 new security patches for Oracle Analytics. 8 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.

Oracle Hyperion Risk Matrix

This Critical Security Patch Update contains 102 new security patches for Oracle Hyperion. 50 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.

Oracle Java SE Risk Matrix

This Critical Security Patch Update contains 3 new security patches for Oracle Java SE. All of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.

Oracle PeopleSoft Risk Matrix

This Critical Security Patch Update contains 16 new security patches for Oracle PeopleSoft. 4 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.

Additional CVEs addressed are:

The patch for CVE-2026-7598 also addresses CVE-2023-48795 and CVE-2023-6918.

Oracle Siebel CRM Risk Matrix

This Critical Security Patch Update contains 63 new security patches for Oracle Siebel CRM. 26 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.

Additional CVEs addressed are:

The patch for CVE-2026-54513 also addresses CVE-2026-54512.

The patch for CVE-2026-55956 also addresses CVE-2026-50229, CVE-2026-53404, CVE-2026-53434, CVE-2026-55276, and CVE-2026-55955.

The patch for CVE-2026-50010 also addresses CVE-2026-44249, CVE-2026-45416, and CVE-2026-45536.

The patch for CVE-2026-54515 also addresses CVE-2026-54512, CVE-2026-54513, and CVE-2026-54514.

Oracle Supply Chain Risk Matrix

This Critical Security Patch Update contains 19 new security patches for Oracle Supply Chain. 5 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.

Oracle Utilities Applications Risk Matrix

This Critical Security Patch Update contains 2 new security patches for Oracle Utilities Applications. 1 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.

Oracle Virtualization Risk Matrix

This Critical Security Patch Update contains 19 new security patches for Oracle Virtualization. 1 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.

This vulnerability applies to Windows host only.

Extracted Entities

CVEs (181)

CVE-2023-48795CVE-2023-6918CVE-2025-68161CVE-2026-0540CVE-2026-10803CVE-2026-10879CVE-2026-13346CVE-2026-13484CVE-2026-13706CVE-2026-13707CVE-2026-14358CVE-2026-14363CVE-2026-14380CVE-2026-14739CVE-2026-14740CVE-2026-3198CVE-2026-34477CVE-2026-34478CVE-2026-34479CVE-2026-34480CVE-2026-39822CVE-2026-4035CVE-2026-41238CVE-2026-41239CVE-2026-41240CVE-2026-41409CVE-2026-41635CVE-2026-41989CVE-2026-41990CVE-2026-42505CVE-2026-42779CVE-2026-44024CVE-2026-44025CVE-2026-44160CVE-2026-44161CVE-2026-44249CVE-2026-45416CVE-2026-45536CVE-2026-45673CVE-2026-45674CVE-2026-46936CVE-2026-47012CVE-2026-47023CVE-2026-47052CVE-2026-47064CVE-2026-47691CVE-2026-48855CVE-2026-48856CVE-2026-48858CVE-2026-48860CVE-2026-48998CVE-2026-49214CVE-2026-49759CVE-2026-49760CVE-2026-50010CVE-2026-50020CVE-2026-50229CVE-2026-53404CVE-2026-53422CVE-2026-53434CVE-2026-54512CVE-2026-54513CVE-2026-54514CVE-2026-54515CVE-2026-54516CVE-2026-54517CVE-2026-54518CVE-2026-54886CVE-2026-54887CVE-2026-55276CVE-2026-55554CVE-2026-55555CVE-2026-55568CVE-2026-55766CVE-2026-55767CVE-2026-55831CVE-2026-55833CVE-2026-55950CVE-2026-55952CVE-2026-55955CVE-2026-55956CVE-2026-56722CVE-2026-56745CVE-2026-56746CVE-2026-57211CVE-2026-57212CVE-2026-57213CVE-2026-57214CVE-2026-57215CVE-2026-57216CVE-2026-57217CVE-2026-57218CVE-2026-57219CVE-2026-57220CVE-2026-57221CVE-2026-58024CVE-2026-58025CVE-2026-58026CVE-2026-58027CVE-2026-58028CVE-2026-58029CVE-2026-58030CVE-2026-58032CVE-2026-58033CVE-2026-58037CVE-2026-58038CVE-2026-58517CVE-2026-58520CVE-2026-58521CVE-2026-59882CVE-2026-59883CVE-2026-59898CVE-2026-59899CVE-2026-59901CVE-2026-59921CVE-2026-59941CVE-2026-59942CVE-2026-59943CVE-2026-60145CVE-2026-60163CVE-2026-60177CVE-2026-60178CVE-2026-60182CVE-2026-60183CVE-2026-60184CVE-2026-60185CVE-2026-60186CVE-2026-60187CVE-2026-60188CVE-2026-60189CVE-2026-60190CVE-2026-60191CVE-2026-60315CVE-2026-60316CVE-2026-60331CVE-2026-60332CVE-2026-60585CVE-2026-60747CVE-2026-61081CVE-2026-61094CVE-2026-61096CVE-2026-61109CVE-2026-61308CVE-2026-64849CVE-2026-67339CVE-2026-67353CVE-2026-67354CVE-2026-67355CVE-2026-69146CVE-2026-69148CVE-2026-70755CVE-2026-73193CVE-2026-73194CVE-2026-73508CVE-2026-7598CVE-2026-8147CVE-2026-83156CVE-2026-83348CVE-2026-83354CVE-2026-87267CVE-2026-87268CVE-2026-87269CVE-2026-87270CVE-2026-87271CVE-2026-87272CVE-2026-87273CVE-2026-87274CVE-2026-87275CVE-2026-87276CVE-2026-87277CVE-2026-87278CVE-2026-87279CVE-2026-87280CVE-2026-87281CVE-2026-87282CVE-2026-87283CVE-2026-87284CVE-2026-87285CVE-2026-87289CVE-2026-8857CVE-2026-9698