Full Report
Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates.Key TakeawaysThe September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates104 issues (15.5% of all patches) were assigned a critical severity ratingOracle E-Business Suite received the highest number of patches at 159, accounting for 23.6% of all patchesBackgroundOn September 15, Oracle released its Critical Security Patch Update (CSPU) for September 2026. Beginning in May 2026, Oracle introduced CSPUs as a monthly release cycle that sits between the larger quarterly Critical Patch Updates (CPUs), addressing a focused set of high-severity issues on a faster cadence. This CSPU contains fixes for 672 unique CVEs in 673 security updates across 17 Oracle product families. Out of the 673 security updates published, 15.5% of patches were assigned a critical severity. High severity patches accounted for the bulk of security patches at 74.7%, followed by critical severity patches at 15.5%.This month's update includes 104 critical patches across 104 CVEs.SeverityIssues PatchedCVEsCritical104104High503503Medium5958Low77Total673672AnalysisThis month's update saw the Oracle E-Business Suite product family contain the highest number of patches at 159, accounting for 23.6% of the total patches, followed by Oracle Fusion Middleware at 153 patches, which accounted for 22.7% of the total patches.A full breakdown of the patches for this CSPU can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication.Oracle Product FamilyNumber of PatchesRemote Exploit without AuthOracle E-Business Suite15919Oracle Fusion Middleware15378Oracle Hyperion10250Oracle Siebel CRM6326Oracle Analytics508Oracle Communications3123Oracle Commerce2716Oracle Supply Chain195Oracle Virtualization191Oracle PeopleSoft164Oracle Database Server115Oracle Enterprise Manager75Oracle Financial Services Applications62Oracle Application Testing Suite30Oracle Java SE33Oracle Autonomous Health Framework21Oracle Utilities Applications21SolutionPatches are available in the September 2026 advisory for full details.Identifying affected systemsA list of Tenable plugins to identify these vulnerabilities will appear here as they're released. This link uses a search filter to ensure that all matching plugin coverage will appear as it is released.Get more informationOracle Critical Security Patch Update Advisory - September 2026Oracle September 2026 Critical Security Patch Update Risk MatricesOracle Advisory to CVE MapJoin Tenable's Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.
Analysis Summary
# Vulnerability: Oracle September 2026 Critical Security Patch Update (CSPU)
## CVE Details
- **CVE ID:** 672 unique CVEs addressed (Individual IDs mapped in vendor advisory)
- **CVSS Score:** Up to 10.0 (104 Critical, 503 High, 59 Medium, 7 Low)
- **CWE:** Multiple (Includes flaws allowing unauthorized network exploitation)
## Affected Systems
- **Products:** 17 Oracle Product Families, most notably:
- Oracle E-Business Suite
- Oracle Fusion Middleware
- Oracle Hyperion
- Oracle Siebel CRM
- Oracle Analytics
- Oracle Communications/Commerce
- Oracle Java SE and Database Server
- **Versions:** Multiple versions across the enterprise stack (Refer to September 2026 Risk Matrices for specific build numbers).
- **Configurations:** Systems accessible over the network are at highest risk; 247 vulnerabilities are exploitable remotely without authentication.
## Vulnerability Description
This update addresses a massive cluster of 672 unique vulnerabilities. While specific technical details vary by CVE, a significant portion (15.5%) are rated **Critical**, and the majority (74.7%) are **High** severity. A primary concern is the high volume of flaws in **Oracle Fusion Middleware (78)** and **Oracle Hyperion (50)** that allow for remote exploitation without requiring user credentials, potentially leading to full system compromise or unauthorized data access.
## Exploitation
- **Status:** Detailed status not specified for every CVE; however, the volume and severity suggest high priority for patching before public PoCs emerge.
- **Complexity:** Variable; many are identified as easily exploitable.
- **Attack Vector:** Primarily **Network** (247 CVEs can be exploited remotely without authentication).
## Impact
- **Confidentiality:** High (Potential for full data exfiltration in critical flaws).
- **Integrity:** High (Potential for unauthorized modification of business-critical data).
- **Availability:** High (Potential for Denial of Service or full system takeover).
## Remediation
### Patches
- Users must apply the security updates released on **September 15, 2026**.
- Monthly CSPUs are now the standard for high-severity issues between quarterly CPUs.
- Specific patch versions are available via the Oracle Support portal.
### Workarounds
- Restrict network access to vulnerable Oracle services, particularly for E-Business Suite and Fusion Middleware.
- Implement strict ingress filtering to prevent "Remote Exploit without Auth" attempts.
- Disable unused Oracle product components or features.
## Detection
- **Indicators of Compromise (IoC):** Look for unusual network traffic directed at Oracle middleware ports and unauthorized administrative changes in E-Business Suite logs.
- **Detection Methods:**
- Utilize Tenable plugins filtered for "(September 2026 CSPU)".
- Scan environments using updated vulnerability management signatures to identify unpatched Oracle instances.
## References
- Oracle Critical Security Patch Update Advisory - September 2026: hxxps[://]www[.]oracle[.]com/security-alerts/cspusep2026[.]html
- Oracle September 2026 Risk Matrices: hxxps[://]www[.]oracle[.]com/security-alerts/cspusep2026verbose[.]html
- Tenable Blog Analysis: hxxps[://]www[.]tenable[.]com/blog/oracle-september-2026-critical-security-patch-update-addresses-672-cves