Skip to content
Oracle Issues Urgent September Security Update Fixing 672 Vulnerabilities Across ...

Oracle Issues Urgent September Security Update Fixing 672 Vulnerabilities Across ...

Linkedin September 16, 2026

Oracle has released an extensive security update addressing 672 distinct vulnerabilities across some of its most widely deployed enterprise products, including E-Business Suite, Fusion Middleware, Hyperion, Siebel CRM, Oracle Database and Java SE.

The September 2026 Critical Security Patch Update contains 673 individual security updates across 17 Oracle product families. The difference between the number of updates and unique vulnerabilities arises because one vulnerability received more than one patch.

Oracle published the update on September 15 and urged affected organisations to deploy the relevant fixes without delay. The company’s E-Business Suite Technology team separately highlighted the release and directed EBS administrators to the supporting patch-availability documents in My Oracle Support.

“Oracle strongly recommends applying the CSPU patches without delay,” the company said.

The scale of the release is substantial. An analysis by Tenable found that 104 of the 673 security updates—15.5% of the total—were classified as Critical. A further 503 were rated High severity, 59 were Medium and seven were Low.

Although the original Oracle E-Business Suite notice is short, the associated risk matrices reveal a much broader security release affecting complex and frequently business-critical enterprise environments.

E-Business Suite receives the largest number of patches

Oracle E-Business Suite was the most heavily represented product family in the September release, receiving 159 new security patches. That accounts for approximately 23.6% of all the updates issued during the month.

According to Oracle’s September 2026 security advisory , 19 of the E-Business Suite vulnerabilities can be exploited remotely without authentication. In practical terms, an attacker may be able to target a vulnerable system over a network without first obtaining a legitimate username, password or authenticated session.

Three E-Business Suite vulnerabilities carry CVSS scores of 9.8 out of 10:

CVE-2026-83327 affects the Personalization component of Oracle Applications Framework and is exploitable through SOAP. CVE-2026-83452 affects the Internal Operations component of Oracle Document Management and Collaboration through HTTP. CVE-2026-83462 affects the MWA Terminal Server component of Oracle Mobile Application Server through TCP.

All three are described as low-complexity, network-accessible vulnerabilities requiring neither privileges nor user interaction. Oracle’s assessment indicates that successful exploitation could have a high impact on confidentiality, integrity and availability.

The affected releases generally include E-Business Suite versions 12.2.3 through 12.2.15, although the precise range differs between vulnerabilities and components. Administrators must therefore consult Oracle’s risk matrix and the relevant My Oracle Support documents rather than assuming that every update applies identically to every EBS deployment.

The release also fixes numerous EBS vulnerabilities rated 8.8. These affect components handling application personalisation, file uploads, diagnostic interfaces, contracts, procurement, maintenance, marketing and other core business functions.

The breadth of affected modules is significant because E-Business Suite is not a single-purpose application. It is an integrated collection of financial, procurement, supply-chain, human-resources, asset-management and customer-facing systems. A compromise can consequently expose far more than an isolated server: it may provide access to financial records, supplier information, employee data, payment workflows and privileged administrative functions.

Database and middleware patches are also required

Patching the E-Business Suite application layer alone may not fully address an organisation’s exposure.

Oracle warned that EBS deployments incorporate Oracle Database and Fusion Middleware components affected by vulnerabilities listed separately in the September advisory. Those issues do not appear in the E-Business Suite risk matrix, even though they may still affect an EBS environment.

Oracle therefore recommends that customers apply the relevant September updates to the database and middleware components supporting their E-Business Suite installations.

This distinction is important for vulnerability-management teams. A scanner, asset inventory or patching programme focused only on products explicitly labelled as “E-Business Suite” could overlook weaknesses in the WebLogic, database, identity or other middleware services on which the application depends.

Organisations should map the complete EBS technology stack, including the deployed EBS release, database version, middleware version, web-facing services, integrations and any externally exposed interfaces. Patch decisions should then be based on the full architecture rather than the headline EBS patch count.

Five maximum-severity Fusion Middleware vulnerabilities

Oracle Fusion Middleware received 153 security patches, the second-largest number assigned to a product family in the September release. Seventy-eight of the vulnerabilities can reportedly be exploited remotely without authentication.

The middleware update includes five vulnerabilities assigned the maximum CVSS score of 10.0:

🚩 CVE-2026-71133 affects the Authentication Engine in Oracle Access Manager.

🚩 CVE-2026-83099 affects Forms Services, client/server and character-mode functionality in Oracle Forms.

🚩 CVE-2026-83059 affects the LDAP Server component of Oracle Internet Directory.

🚩 CVE-2026-83020 affects centralised third-party Java libraries in Oracle Platform Security for Java.

🚩 CVE-2026-83021 affects the Web Container in Oracle WebLogic Server.

Oracle characterises all five as remotely exploitable, low-complexity vulnerabilities that require no privileges or user interaction. Successful exploitation could result in severe consequences for the confidentiality, integrity and availability of affected systems.

The WebLogic vulnerability is particularly relevant because WebLogic is widely used as the application-server layer behind critical enterprise services. The affected versions listed by Oracle include 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Organisations using WebLogic should verify the precise products and versions in their environments and apply the appropriate patches supplied through Oracle support channels.

Several other Fusion Middleware vulnerabilities have CVSS scores of 9.8. They affect Oracle Identity Manager, Oracle Internet Directory, Oracle JDeveloper, Oracle Platform Security for Java, WebCenter products and WebLogic Server.

Three 9.8-rated WebLogic vulnerabilities— CVE-2026-70748 , CVE-2026-70756 and CVE-2026-70757 —affect the product’s Core component and can be targeted through the T3 and IIOP protocols without authentication. Oracle lists WebLogic releases 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 among the affected versions, depending on the vulnerability.

The concentration of unauthenticated vulnerabilities in middleware means organisations should give particular attention to management interfaces, application endpoints and protocols reachable from untrusted networks. Systems exposed directly to the internet—or accessible from less trusted internal segments—will generally carry greater immediate risk.

Hyperion, Siebel and Analytics also heavily affected

Oracle Hyperion received 102 new security patches, including 50 addressing vulnerabilities that Oracle says may be remotely exploited without authentication.

Hyperion platforms are commonly used for financial consolidation, planning, reporting and enterprise performance management. Their proximity to sensitive financial data makes them attractive targets even where a vulnerability does not provide immediate control of an underlying operating system.

Oracle Siebel CRM received 63 patches, with 26 vulnerabilities remotely exploitable without credentials. Oracle Analytics received 50 patches, eight of which fall into the unauthenticated remote-exploitation category.

Other affected product families include Oracle Communications, with 31 patches and 23 remotely exploitable without authentication; Oracle Commerce, with 27 patches and 16 unauthenticated issues; and Oracle Supply Chain, with 19 patches, five of which can be attacked remotely without credentials.

Oracle Virtualization also received 19 updates, while PeopleSoft received 16. Database Server was assigned 11 new patches, five covering vulnerabilities remotely exploitable without authentication. Enterprise Manager received seven updates, five of which can be targeted without credentials.

The database updates include CVE-2026-83351 , an unauthenticated network vulnerability rated 8.1. Oracle also said two Database Server patches apply to client-only installations, demonstrating that systems without a locally installed database server should not automatically be considered unaffected.

Oracle Java SE received three security patches, all of which Oracle classifies as remotely exploitable without authentication.

The risk extends beyond internet-facing systems

The phrase “remotely exploitable without authentication” is an important prioritisation indicator, but organisations should not treat it as the only measure of risk.

Many of the September vulnerabilities require a low-privileged account rather than no account at all. Such weaknesses can be highly valuable after an attacker gains initial access through phishing, stolen credentials, malware or an unrelated internet-facing vulnerability.

In an E-Business Suite environment, a vulnerability requiring ordinary user access could potentially be used to elevate privileges, retrieve information outside the user’s authorised role, manipulate business records or move into more sensitive application functions.

Enterprise platforms also tend to possess extensive trust relationships. EBS, WebLogic, identity systems, databases and analytics platforms may communicate with directory services, file repositories, payment systems, mail infrastructure and third-party applications. Compromising one component can therefore create opportunities to steal credentials, abuse application integrations or move laterally into other parts of the network.

The risk can be greater in environments where application accounts have accumulated excessive permissions, older modules remain enabled, administrative interfaces are reachable from broad network segments or obsolete software remains in production.

Monthly updates change Oracle’s patching model

The September release is part of Oracle’s newer Critical Security Patch Update programme, which began in May 2026.

Traditional Oracle Critical Patch Updates are cumulative collections released quarterly on the third Tuesday of January, April, July and October. The newer CSPUs are more focused releases intended to deliver high-priority security fixes during the intervening months.

According to Oracle’s security-patch schedule , CSPUs are released in February, March, May, June, August, September, November and December. Taken together with the quarterly CPU schedule, that establishes a monthly security-release cycle.

Oracle describes CSPUs as smaller, targeted packages intended to make high-priority updates easier to deploy with less disruption. However, the September package—comprising hundreds of updates—shows that even an interim release can require considerable assessment, testing and change-management work in a large enterprise.

The quarterly Critical Patch Update is scheduled for October 20, 2026. Further CSPUs are scheduled for November 17 and December 15.

Organisations that still structure Oracle patching exclusively around the historic quarterly cycle will need to adjust their processes. Waiting for the quarterly maintenance window could leave severe, remotely exploitable vulnerabilities unaddressed for weeks or months.

Supported releases and legacy-system exposure

Oracle provides CSPU patches only for product versions covered by Premier Support or Extended Support.

The company cautioned that unsupported releases are not tested to determine whether the newly fixed vulnerabilities affect them. That does not mean older versions are secure. Oracle said earlier releases are likely to be affected in some cases and advised customers to upgrade to supported software.

This creates a difficult problem for organisations running legacy Oracle platforms. An older deployment may contain vulnerable code but lack an official patch, forcing the operator to choose between upgrading, isolating the application, implementing compensating controls or accepting significant residual risk.

Unsupported installations should consequently receive increased scrutiny. Security teams should identify any Oracle products outside their supported lifecycle and document the business owner, exposure, existing controls and migration plan for each system.

Oracle recommends immediate patching, not workarounds

Oracle said some attack paths may be reduced temporarily by blocking the network protocols required for exploitation or withdrawing unnecessary privileges and package access.

These measures can reduce exposure but are not substitutes for patching. Oracle warned that such changes may break application functionality and should be tested on non-production systems before deployment.

The company explicitly said neither approach corrects the underlying vulnerability.

For most organisations, an effective response should begin with identifying every affected Oracle product and version, including supporting database and middleware components. Security teams should then prioritise internet-facing services, maximum-severity vulnerabilities, unauthenticated attack paths and systems holding sensitive financial, identity or operational data.

Patches should be tested against representative non-production environments, with particular attention paid to integrations, authentication flows, customisations, batch jobs and business-critical transactions. Where an immediate update is impossible, access should be restricted at the network layer, unnecessary services should be disabled and monitoring should be increased around affected endpoints and privileged accounts.

Administrators should also review whether earlier Oracle security releases were skipped. Oracle’s risk matrices list only vulnerabilities newly addressed in the current update; an organisation that missed CPUs or CSPUs may remain exposed to older flaws even after installing a subset of September’s patches.

No indication of active exploitation in Oracle’s advisory

Oracle’s September advisory does not state that the newly disclosed vulnerabilities are being actively exploited in the wild. That absence should not be interpreted as evidence that exploitation is impossible or will not follow.

Once a vendor publishes patch details, affected components and severity information, attackers can compare updated and unpatched code to identify the underlying changes. This process, often called patch diffing, can accelerate the development of working exploits.

The threat is particularly acute for remotely accessible vulnerabilities that require no credentials and little attack complexity. The five CVSS 10.0 middleware vulnerabilities and the three 9.8-rated unauthenticated EBS flaws should therefore receive urgent attention even without public reports of exploitation.

Oracle’s September 2026 security release ultimately presents two challenges for enterprise defenders: the immediate task of addressing hundreds of vulnerabilities and the longer-term requirement to adapt patch-management programmes to Oracle’s monthly release cycle.

For E-Business Suite operators, the central message is especially clear. Applying the EBS patches is only one part of the remediation effort. Organisations must also evaluate the Oracle Database, Fusion Middleware and other shared components underpinning their deployment—or risk leaving critical weaknesses in place after the application layer has been updated.

Cyber Security Hub

To view or add a , sign in