Oracle Patches 800+ Vulnerabilities in September 2026 Security Update

https://www.securityweek.com/wp-content/uploads/2023/01/Cybersecurity_News-SecurityWeek.jpg

Oracle on Tuesday announced the release of 673 new security patches as part of its September 2026 Critical Security Patch Update (CSPU).

The security updates appear to resolve more than 800 vulnerabilities: there are 672 unique CVEs in the 17 risk matrices included in the September 2026 CSPU advisory, but Oracle also notes that more than 130 additional CVEs have been resolved with the patches for other flaws.

More than 100 of the newly addressed security defects are critical-severity flaws, and over 240 are remotely exploitable without authentication.

Oracle E-Business Suite received 159 security patches, the largest batch of the CSPU. 19 of the vulnerabilities can be exploited remotely without authentication.

Fusion Middleware followed closely, receiving 153 patches, including fixes for 78 unauthenticated, remotely exploitable flaws. Hyperion was third, with 102 patches (50 remotely exploitable without authentication).

Oracle also rolled out a significant number of patches for Siebel CRM...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE