Oracle has released one of its largest monthly security bundles to date, shipping 673 new security patches in its September 2026 Critical Security Patch Update (CSPU) to close serious flaws spanning its enterprise software portfolio.
The advisory, published on September 15, spans 17 product families and includes more than 100 critical-severity vulnerabilities, with over 240 flaws remotely exploitable without authentication, meaning an attacker can weaponize them over a network without valid credentials.
While the headline figure is 673 patches, the true scope is broader. Oracle’s advisory contains 672 unique CVEs across its published risk matrices, but the vendor notes that more than 130 additional CVEs have been quietly resolved through patches bundled for other flaws, pushing the effective total past 800 vulnerabilities remediated in a single release.
This blurs the traditional line between Oracle’s lighter monthly CSPUs and its heavier quarterly Critical Patch Updates (CPUs), a trend that has accelerated throughout 2026.
Oracle September Security Update
The CSPU is a relatively new addition to Oracle’s security program, first introduced in May 2026 as a targeted, high-priority release designed to be easier to deploy with minimal operational disruption.
These updates are issued on the third Tuesday of February, March, May, June, August, September, November, and December, filling the gaps between the cumulative quarterly CPUs released each January, April, July, and October.
According to the security advisory published by Oracle, the goal is to shrink the window during which known vulnerabilities remain exploitable in customer environments. The next scheduled releases are a CPU on October 20, followed by CSPUs on November 17 and December 15.
Oracle E-Business Suite absorbed the largest share of fixes with 159 patches, 19 of them remotely exploitable without authentication.
Fusion Middleware followed closely with 153 patches, a particularly alarming batch given that 78 of those flaws are unauthenticated and network-exploitable, the kind of exposure that maps directly to internet-facing enterprise infrastructure. Hyperion ranked third with 102 patches, half of which require no authentication to exploit.
Beyond the top three, Oracle distributed substantial fixes across Siebel CRM (63), Analytics (50), Communications (31), Commerce (27), Supply Chain (19), Virtualization (19), and PeopleSoft (16).
The Communications update is notable because roughly half of its patches resolve more than 125 additional CVEs, largely rooted in bundled third-party components.
Additional families receiving attention include Database Server, Enterprise Manager, Financial Services Applications, Application Testing Suite, Java SE, Autonomous Health Framework, and Utilities Applications.
Oracle makes no mention of any of these specific September vulnerabilities being exploited in the wild, but the company issued a familiar and pointed warning.
It continues to receive reports of attackers succeeding against organizations that simply failed to apply patches already available a recurring pattern where the gap between disclosure and remediation becomes the attacker’s entry point.
That risk is not theoretical: earlier in 2026, CISA gave federal agencies just 72 hours to remediate an actively exploited Oracle flaw (CVE-2026-21962, CVSS 10.0) that had been patched months earlier.
Given the volume of unauthenticated, remotely exploitable flaws in this release, security teams should prioritize internet-exposed Fusion Middleware, E-Business Suite, and Hyperion deployments first.
Oracle strongly urges customers to remain on actively supported versions and to apply the patches without delay. Full patch availability documents and per-product risk matrices are available in the official September 2026 CSPU advisory.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
The post Oracle Critical Security Update – 673 Vulnerabilities Patched Across Product Families appeared first on Cyber Security News.
