Oracle Critical Security Patch Update, September 2026 Review

Imported from official source

Cybersecurity Classified by Officially

Oracle released its September edition of Critical Security Patch Update. The update received patches for 673 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products. 

Out of the 673 security updates published, a total of 104 (15.5%) vulnerabilities are rated critical, 503 are rated as important (74.7%), and 59 are rated as medium. 

In this Oracle Critical Security Patch Update, Oracle E-Business Suite received the highest number of patches, 159, constituting about 24% of the total patches released.

41 of the 673 (about 6%) security patches in the September Critical Security Patch Update are for non-Oracle CVEs, such as open-source components included in, and exploitable within, Oracle product distributions.

This batch of security patches received 13 updates for Oracle Database products. The following is the product-wise distribution: 

  • 11 new security updates for Oracle Database Server with a maximum reported CVSS Base Score of 8.8. 
    • 2 of these updates apply to client-only deployments of the Oracle Database. 
  • 2 new security updates for Oracle Autonomous Health Framework with a maximum reported CVSS Base Score of 7.5. 

The complete list of Oracle product families and the no of patches issued are listed below:

Oracle Product FamilyNo. of PatchesRemote Exploit without AuthenticationOracle E-Business Suite 159 19 Oracle Fusion Middleware 153 78 Oracle Hyperion 102 50 Oracle Siebel CRM 63 26 Oracle Analytics 50 8 Oracle Communications 31 23 Oracle Commerce 27 16 Oracle Supply Chain 19 5 Oracle Virtualization 19 1 Oracle PeopleSoft 16 4 Oracle Database Server 11 5 Oracle Enterprise Manager 7 5 Oracle Financial Services Applications 6 2 Oracle Application Testing Suite 3 0 Oracle Java SE 3 3 Oracle Autonomous Health Framework 2 1 Oracle Utilities Applications 2 1 

Qualys QID Coverage

This is an extract. The publication continues at the source.

Read the original at the source: https://blog.qualys.com/vulnerabilities-threat-research/2026/09/16/oracle-critical-security-patch-update-september-2026-review

Officially imported this from Qualys’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Qualys — imported from official source
Official source
https://blog.qualys.com/feed RSS
Imported
September 20, 2026 19:52
Versions
1 recorded
Identity
https://blog.qualys.com/?p=42354

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.