The September 2026 Oracle Critical Patch Update is one of the largest waves of security updates the company has ever released, with 673 new security patches addressing a total of more than 800 vulnerabilities . Oracle officially announced the release of the September 2026 Critical Security Patch Update (CSPU) on Tuesday , a milestone that highlights the vast breadth of the attack surface that the company’s products present globally.
According to official figures, the CSPU includes 672 unique CVEs distributed across 17 risk matrices, while over 130 additional CVEs are addressed through the same patches for various vulnerabilities. Of these, over 100 are rated critical, while over 240 can be exploited remotely without any authentication — a highly concerning issue for organizations that expose Oracle online.
The size of this update is no coincidence. Oracle maintains one of the most extensive enterprise software portfolios in the world, covering areas from databases and ERP systems to cloud infrastructure and Java. Each Critical Patch Update reflects the accumulation of vulnerabilities discovered both internally and by independent security researchers, making these updates absolutely critical for any organization using Oracle.
See also: Oracle CSPU June 2026: 245 patches for critical vulnerabilities

Oracle Critical Patch Update: Which products are most affected?
Oracle E-Business Suite received the most patches in the September 2026 CSPU, with 159 security patches in total. Of these, 19 vulnerabilities can be exploited remotely without authentication, making it urgent for organizations that use E-Business Suite for critical business functions such as finance, human resources, and supply chain management to apply the updates.
Oracle Fusion Middleware is next with 153 patches , 78 of which are for vulnerabilities that can be exploited remotely without authentication . Fusion Middleware is the backbone of many Oracle enterprise applications, including WebLogic Server , Oracle HTTP Server , and other middleware solutions widely used in enterprise environments. The high number of remotely exploitable vulnerabilities in this component is particularly concerning, as WebLogic exploits have been widely used by ransomware groups and state-sponsored threat actors in the past.
Oracle Hyperion, the business intelligence and financial management platform, received 102 patches, with 50 of them addressing vulnerabilities that could be exploited remotely without authentication. Since Hyperion is used by large enterprises for financial planning and reporting, vulnerabilities in this system can have serious implications for both data confidentiality and regulatory compliance.

A significant number of patches were also released for Oracle Siebel CRM ( 63 patches ), Oracle Analytics ( 50 patches ), Oracle Communications ( 31 patches ), Oracle Commerce ( 27 patches ), Oracle Supply Chain ( 19 patches ), Oracle Virtualization ( 19 patches ), and PeopleSoft ( 16 patches ). The Oracle Communications update is of particular note , as half of its patches resolve over 125 additional CVEs — an impressive number that suggests deep dependencies on third-party libraries and components.
Oracle Critical Patch Update: Technical Analysis and Risks
In addition to the above, the September 2026 Critical Patch Update includes updates for a number of other critical Oracle: Oracle Database Server, Oracle Enterprise Manager, Oracle Financial Services Applications, Oracle Application Testing Suite, Java SE, Oracle Autonomous Health Framework , and Oracle Utilities Applications.
See also: Oracle July Patch Update: 1,449 fixes and 10 critical security vulnerabilities
Oracle has not said that any of these vulnerabilities are being actively exploited in attacks. However, the company explicitly warns that threat actors regularly exploit vulnerabilities in its products and urges customers to apply the updates as soon as possible. This warning is not typical — historically, vulnerabilities in Oracle WebLogic and Oracle E-Business Suite have been exploited by ransomware and APT groups within days of the release of patches, as attackers analyze the updates to find the weak points.
One of the most concerning features of this update is the large number of vulnerabilities that are remotely exploitable without authentication . This means that an attacker does not need any prior access or credentials to exploit these vulnerabilities — all they need is network access to the vulnerable system . In environments where Oracle systems are exposed to the Internet or in poorly segmented corporate networks, this poses an extremely serious risk.

How to protect yourself from Oracle vulnerabilities
For organizations using Oracle products, immediate implementation of the September 2026 CSPU is absolutely essential. However, beyond applying patches, there are other measures that can significantly reduce the risk. First, organizations should review the exposure of Oracle systems to the internet and implement strict firewall rules that limit access to authorized sources only. The principle of least privilege should be applied at both the network and application levels.
See also: SAP Security Patch Day September 2026: New security fixes
Second, security teams should actively monitor Oracle systems for suspicious activity, especially in the coming weeks, as this is the period when attackers are most likely to attempt to exploit the new vulnerabilities. Using SIEM and EDR solutions , which can detect anomalous behavior in Oracle systems, is particularly helpful. Third, network segmentation can significantly limit the lateral movement of an attacker who has managed to gain initial access through an Oracle vulnerability .
