Skip to content
Oracle patches over 650 security vulnerabilities

Oracle patches over 650 security vulnerabilities

Heise.De September 16, 2026

Oracle observes the Critical Security Patch Update (CSPU) patch day in September around the middle of the month. The company’s developers are providing 673 software patches for various products from their portfolio.

IT managers should study the listed issues in the patch day overview more closely and check if they are using the vulnerable products from the portfolio. Some products require prompt attention as they are affected by vulnerabilities classified as critical risk by Oracle’s developers. Attackers can cause greater damage as a result, which admins can prevent by applying the updates in a timely manner.

Security vulnerabilities classified as critical risk according to CVSS rating are found in

Oracle Application Testing Suite, Oracle Communications Unified Assurance, Oracle Applications Framework, Oracle Document Management and Collaboration, Oracle Mobile Application Server, Oracle Enterprise Manager Base Platform, Oracle Enterprise Manager for Fusion Middleware, Oracle Access Manager, Oracle Forms, Oracle Internet Directory, Oracle Platform Security for Java, Oracle WebLogic Server, Oracle WebCenter Portal, Oracle WebCenter Sites, Service Delivery Platform, Oracle Data Integrator, Oracle Identity Manager, Oracle WebCenter Enterprise Capture, Oracle Managed File Transfer, Oracle Identity Manager Connector, Oracle Business Intelligence Enterprise Edition, Oracle BI Publisher, Oracle Hyperion Financial Management, Oracle Hyperion Data Relationship Management, Siebel Apps - Financial Services, Siebel CRM Deployment, Siebel CRM End User, Oracle Product Lifecycle Analytics, and in Oracle Agile PLM.

However, numerous other vulnerabilities are also classified as high-risk by the company’s programmers. Admins should not postpone these updates either to reduce the attack surface of their own IT.

A critical security patch update also took place in August. However, Oracle had to fix almost 1000 vulnerabilities in various products there. In October 2026, the patch day called Oracle Critical Patch Update (CPU), which is carried out quarterly according to the original schedule, will take place again.

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.