Skip to content
Oracle Releases September 2026 Critical Security Patch Update Advisory

Oracle Releases September 2026 Critical Security Patch Update Advisory

Digital.Nhs.Uk September 16, 2026

Scheduled advisory includes 673 security updates across multiple Oracle product families

Scheduled advisory includes 673 security updates across multiple Oracle product families

The following platforms are known to be affected:

Oracle E-Business Suite

Oracle Communications

The following platforms are also known to be affected:

Multiple other Oracle product families. Please see Oracle's Critical Security Patch Update Advisory - September 2026 guide for full details.

Oracle has released the Critical Security Patch Update Advisory for September 2026 addressing 673 security updates across multiple Oracle product families.

Of note are vulnerabilities CVE-2026-83327, CVE-2026-83452, and CVE-2026-83462 with a CVSS v3.1 score: 9.8 which, if exploited, could allow a remote, unauthenticated attacker to takeover over Oracle E-Business Suite components.

Affected organisations are encouraged to review Oracle's Critical Security Patch Update Advisory - September 2026 and apply the relevant updates as soon as possible.

Definitive source of threat updates

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Document Management and Collaboration. Successful attacks of this vulnerability can result in takeover of Oracle Document Management and Collaboration. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application Server. Successful attacks of this vulnerability can result in takeover of Oracle Mobile Application Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Last edited: 16 September 2026 2:54 pm