ORACLE has issued 673 security patches in its September 2026 Critical Security Patch Update (CSPU), addressing 672 unique CVEs across 17 risk matrices. Oracle also says the patches fix more than 130 additional CVEs, bringing the total number of vulnerabilities addressed to more than 800. Over 100 of the newly fixed flaws are rated critical, while more than 240 can reportedly be exploited remotely without authentication.
Oracle E-Business Suite received the largest set of fixes, with 159 patches, including 19 for unauthenticated, remotely exploitable vulnerabilities. Fusion Middleware received 153 patches, including 78 in that category, followed by Hyperion with 102 patches, 50 of which are remotely exploitable without authentication. Other significant updates cover Siebel CRM, Analytics, Communications, Commerce, Supply Chain, Virtualization and PeopleSoft.
Oracle did not say that any of the vulnerabilities are being exploited in the wild. However, it warned that attackers regularly target flaws in its products and said organisations have previously been compromised after failing to install available patches. Oracle recommends that customers use actively supported product versions and apply the September updates without delay.