Oracle has released its September 2026 Critical Security Patch Update, addressing 673 new security patches across the affected Oracle product families.
The Fortra Intelligence and Research Experts (FIRE) team is reviewing the release and prioritizing coverage for vulnerabilities that combine remote reachability, low attack complexity, and high business impact.
At a Glance
| Metric | Value |
|---|---|
| New security patches | 673 |
| Unique CVEs in the risk matrices | 672 |
| Remotely exploitable without authentication | 246 unique CVEs |
| CVSS 9.0 or higher | 104 unique CVEs |
| Highest CVSS 3.1 base score | 10.0 |
Vulnerabilities to Watch
Oracle Access Manager | Authentication Engine | CVSS 10.0 | HTTP
Remote without authentication | Complexity: Low | User interaction: None
Affected versions: 12.2.1.4.0, 14.1.2.1.0
The Oracle Access Manager is subject to a complete compromise via an unauthenticated attacker who targets the Authentication Engine via HTTP. Since the authentication manager is often placed in front of web applications to control access, there is a strong likelihood that it is exposed to the Internet, increasing the risk presented by this vulnerability.
Oracle Platform Security for Java | Centralized Thirdparty Jars | CVSS 10.0 | HTTP
Remote without authentication | Complexity: Low | User interaction: None
Affected versions: 12.2.1.4.0, 14.1.2.0.0
When you see Centralized Thirdparty Jars, this is a collection of open-source libraries managed as part of Oracle Platform Security for Java, a security framework for Java applications. It provides capabilities such as XML and JSON parsers, networking and HTTP utilities, and input validation and serialization libraries. An unauthenticated attacker targeting HTTP could successfully compromise Oracle Platform Security for Java.
Oracle WebLogic Server | Web Container | CVSS 10.0 | HTTP
Remote without authentication | Complexity: Low | User interaction: None
Affected versions: 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0
This remote, unauthenticated vulnerability exists within the core component of the Oracle WebLogic Server, which is responsible for processing incoming HTTP requests and generating dynamic responses. The very nature of this tool means that it will likely be exposed to the public Internet, increasing the risk to these systems should exploit code be developed.
Oracle Forms | Forms Services, C/S, Charmode | CVSS 10.0 | HTTP
Remote without authentication | Complexity: Low | User interaction: None
Affected versions: 12.2.1.19.0, 14.1.2.0.0
Oracle Forms allows users to develop database-driven applications for a variety of environments. Charmode allows for development for text-based systems, while C/S (Client/Server mode) is designed for GUI Desktop applications. Finally, Forms Services provides a web-based approach to the process. With this vulnerability, all three contain a remote, unauthenticated vulnerability that could lead to a complete compromise.
Product Family Breakdown
The following product families account for the largest patch volumes in this release. Review Oracle's full risk matrices and Patch Availability Documents for complete product and version details.
| Product family | Patches | Remote / no auth | Max CVSS |
|---|---|---|---|
| Oracle E-Business Suite | 159 | 19 | 9.8 |
| Oracle Fusion Middleware | 153 | 78 | 10.0 |
| Oracle Hyperion | 102 | 50 | 10.0 |
| Oracle Siebel CRM | 63 | 26 | 9.1 |
| Oracle Analytics | 50 | 8 | 9.9 |
| Oracle Communications | 31 | 23 | 9.8 |
| Oracle Commerce | 27 | 16 | 8.2 |
| Oracle Supply Chain | 19 | 5 | 9.8 |
| Oracle Virtualization | 19 | 1 | 8.6 |
| Oracle PeopleSoft | 16 | 4 | 8.8 |
Remediation Guidance
Organizations should inventory affected Oracle products and versions, review the applicable Patch Availability Documents in My Oracle Support, and prioritize internet-facing or otherwise exposed systems. Particular attention should be given to unauthenticated network vulnerabilities with low attack complexity and high confidentiality, integrity, or availability impacts.
Critical Security Patch Updates provide targeted high-priority fixes between quarterly cumulative CPUs. Organizations that have skipped releases should review previous CPU and CSPU advisories to determine the complete patching requirements for their environments.
Where immediate patching is not possible, reduce exposure to affected protocols, restrict unnecessary privileges, monitor for suspicious activity, and test temporary changes before production use. These measures do not replace applying the Critical Security Patch Update.
Sources
Oracle advisory: https://www.oracle.com/security-alerts/cspusep2026.html
Text-form risk matrices: https://www.oracle.com/security-alerts/cspusep2026verbose.html
Oracle security advisories index: https://www.oracle.com/security-alerts/