Oracle has shipped its September 2026 Critical Security Patch Update (CSPU), delivering 673 security fixes that collectively resolve more than 800 vulnerabilities across 17 product families.[1][3][6] The company’s advisory lists 672 unique CVE identifiers in the risk matrices, while noting that additional CVEs are addressed as part of composite patches targeting related flaws.[1][3]
In its breakdown of the release, Oracle and independent analysis highlight that more than 100 of the newly addressed vulnerabilities are rated critical severity, with over 240 flaws remotely exploitable without authentication over the network.[3][6][11] The CSPU was published on September 15, 2026, and Oracle classifies it as a revision 1 advisory, underscoring the expectation that customers begin planning deployment immediately.[1][2][4]
The update covers a broad swath of the Oracle portfolio, including Database Server, Enterprise Manager, Financial Services Applications, Application Testing Suite, Java SE, Autonomous Health Framework, Communications products, E-Business Suite, Fusion Middleware, Analytics, Hyperion, PeopleSoft, Siebel CRM, Supply Chain and Utilities Applications, among others.[1][3][4] Third-party analysis notes that Oracle E-Business Suite and Fusion Middleware receive the largest share of patches in this cycle, reflecting the complexity and exposure of these business-critical platforms.[4][6][11]
Several individual bugs stand out for their potential impact. The advisory, for example, calls out CVE-2026-71133 in Oracle Access Manager’s Authentication Engine, a remotely exploitable vulnerability with a CVSS v3.1 base score of 10.0 that can be abused over HTTP with low privileges and no user interaction, leading to a full compromise of confidentiality, integrity and availability.[1] Another critical issue, CVE-2026-83099 in Oracle Forms Services, also carries a CVSS score of 10.0 and can be triggered remotely without authentication, affecting multiple supported Forms versions.[1] Oracle Communications Unified Assurance is affected by CVE-2026-71290, a high-severity flaw scored 9.1 that is likewise remotely exploitable and could be attractive to attackers targeting telco and service-provider environments.[1][3]
Oracle notes that eight of the vulnerabilities in certain product families may be exploited remotely without authentication, increasing the risk for organizations with internet-facing Oracle deployments that have not yet applied the CSPU.[1][3] The advisory also confirms that a patch associated with CVE-2026-7598 addresses previously disclosed issues in SSH connection handling, including CVE-2023-48795 and CVE-2023-6918, which were widely discussed in the context of man-in-the-middle and traffic manipulation attacks.[1] While the vendor does not flag any of the newly fixed bugs as being actively exploited at the time of release, the concentration of critical and unauthenticated remote vulnerabilities suggests that exploit development is likely to follow quickly, particularly for widely deployed middleware and ERP components.[1][3][6]
For defenders, the guidance is clear: prioritize testing and deployment of the September CSPU across exposed Oracle instances, starting with E-Business Suite, Fusion Middleware, Access Manager, Forms and Communications products that are reachable from the internet or untrusted network segments.[3][4][6] Oracle’s security team urges customers to apply the patches as soon as possible and to consult product-specific documentation and risk matrices to understand which supported versions are affected and how best to sequence updates in complex environments.[1][4][7] Organizations that rely on Oracle software for core business operations should also review compensating controls—such as tightening access controls, increasing monitoring on Oracle services and validating backups—while patch rollouts are underway.[3][6]
References
- Oracle Critical Security Patch Update Advisory – September 2026
- Critical Patch Updates, Critical Security Patch Updates, Security Alerts and Bulletins
- Oracle Patches 800+ Vulnerabilities in September 2026 Security Update
- September 2026 Critical Security Patch Update Released
- Oracle September 2026 Critical Security Patch Update
- Critical Security Patch Update for September 2026 Now Available
- Oracle September 2026 Critical Security Patch Update
