LIVE · cybersecurity feed
Live wire
vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

zeroday.news ·

Photo: Gregory Varnum (CC BY-SA 4.0) via Wikimedia Commons

Oracle released its September 2026 Critical Security Patch Update (CSPU) on September 15, addressing 672 unique Common Vulnerabilities and Exposures (CVEs) through 673 security updates across 17 product families. This monthly release cycle, introduced in May 2026, aims to provide a faster cadence for high-severity issues compared to the quarterly Critical Patch Updates (CPUs).

Of the 673 security updates, 104 (15.5%) were assigned a critical severity rating, while 503 (74.7%) were classified as high severity. The remaining patches included 59 medium severity and 7 low severity issues.

The Oracle E-Business Suite product family received the highest number of patches in this update, with 159 fixes, accounting for 23.6% of the total. Following closely was Oracle Fusion Middleware, with 153 patches (22.7%). Oracle Hyperion received 102 patches, and Oracle Siebel CRM had 63.

A significant portion of these vulnerabilities could be exploited remotely without requiring authentication. Oracle Fusion Middleware had the most such vulnerabilities, with 78, followed by Oracle Hyperion with 50, and Oracle Siebel CRM with 26. Oracle E-Business Suite included 19 vulnerabilities exploitable remotely without authentication.

Other product families receiving patches included Oracle Analytics (50 patches), Oracle Communications (31), Oracle Commerce (27), Oracle Supply Chain (19), Oracle Virtualization (19), Oracle PeopleSoft (16), Oracle Database Server (11), Oracle Enterprise Manager (7), Oracle Financial Services Applications (6), Oracle Application Testing Suite (3), Oracle Java SE (3), Oracle Autonomous Health Framework (2), and Oracle Utilities Applications (2).

The patches for these vulnerabilities are detailed in the September 2026 advisory.

vulnerabilitypatchfinance
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Hackers target WordPress sites via third-party WooCommerce plugin

Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [...]

malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

malware

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

'Enemies of the regime' on notice

patch

Before You Patch. Why Patch Reliability Matters for Confident Deployment

Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security patching. Qualys TruRisk Eliminate classified both updates as Low Reliability, signaling the need for additional validation before production deployment. Patch Reliability helps IT and s