Oracle released its September 2026 Critical Security Patch Update (CSPU) on September 15, addressing 672 unique Common Vulnerabilities and Exposures (CVEs) through 673 security updates across 17 product families. This monthly release cycle, introduced in May 2026, aims to provide a faster cadence for high-severity issues compared to the quarterly Critical Patch Updates (CPUs).
Of the 673 security updates, 104 (15.5%) were assigned a critical severity rating, while 503 (74.7%) were classified as high severity. The remaining patches included 59 medium severity and 7 low severity issues.
The Oracle E-Business Suite product family received the highest number of patches in this update, with 159 fixes, accounting for 23.6% of the total. Following closely was Oracle Fusion Middleware, with 153 patches (22.7%). Oracle Hyperion received 102 patches, and Oracle Siebel CRM had 63.
A significant portion of these vulnerabilities could be exploited remotely without requiring authentication. Oracle Fusion Middleware had the most such vulnerabilities, with 78, followed by Oracle Hyperion with 50, and Oracle Siebel CRM with 26. Oracle E-Business Suite included 19 vulnerabilities exploitable remotely without authentication.
Other product families receiving patches included Oracle Analytics (50 patches), Oracle Communications (31), Oracle Commerce (27), Oracle Supply Chain (19), Oracle Virtualization (19), Oracle PeopleSoft (16), Oracle Database Server (11), Oracle Enterprise Manager (7), Oracle Financial Services Applications (6), Oracle Application Testing Suite (3), Oracle Java SE (3), Oracle Autonomous Health Framework (2), and Oracle Utilities Applications (2).
The patches for these vulnerabilities are detailed in the September 2026 advisory.






