Oracle Patches 800+ Vulnerabilities in September 2026 Security Update
Oracle released a massive security update containing over 800 patches to address a wide range of vulnerabilities across its products. The update focuses on preventing exploitation by threat actors, highlighting that delays in patching can lead to successful attacks. Oracle urges immediate application of these patches to mitigate risk.
Oracle announced the release of a substantial security update, the September 2026 Critical Security Patch Update (CSPU), containing over 800 security patches. This update addresses a significant number of vulnerabilities across its diverse product portfolio. The CSPU includes 672 unique CVEs within the 17 risk matrices provided in the advisory, with an additional 130 vulnerabilities resolved through other patches.
Oracle E-Business Suite received the largest batch of patches, with 159 fixes. Fusion Middleware followed closely, receiving 153 patches, including 78 unauthenticated, remotely exploitable flaws. Hyperion received 102 patches, with 50 of these being remotely exploitable without authentication. Other products receiving updates include Siebel CRM (63), Analytics (50), Communications (31), Commerce (27), Supply Chain (19), Virtualization (19), and PeopleSoft (16).
Oracle states that it has observed threat actors successfully exploiting vulnerabilities due to delayed patching. The company strongly advises customers to apply these security updates promptly to minimize the risk of exploitation.
Oracle has not indicated whether any of these vulnerabilities are currently being actively exploited in the wild, but emphasizes the importance of proactive patching to prevent attacks.