Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates.
Key Takeaways
- The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates
- 104 issues (15.5% of all patches) were assigned a critical severity rating
- Oracle E-Business Suite received the highest number of patches at 159, accounting for 23.6% of all patches
Background
On September 15, Oracle released its Critical Security Patch Update (CSPU) for September 2026. Beginning in May 2026, Oracle introduced CSPUs as a monthly release cycle that sits between the larger quarterly Critical Patch Updates (CPUs), addressing a focused set of high-severity issues on a faster cadence. This CSPU contains fixes for 672 unique CVEs in 673 security updates across 17 Oracle product families. Out of the 673 security updates published, 15.5% of patches were assigned a critical severity. High severity patches accounted for the bulk of security patches at 74.7%, followed by critical severity patches at 15.5%.

This month's update includes 104 critical patches across 104 CVEs.
| Severity | Issues Patched | CVEs |
|---|---|---|
| Critical | 104 | 104 |
| High | 503 | 503 |
| Medium | 59 | 58 |
| Low | 7 | 7 |
| Total | 673 | 672 |
Analysis
This month's update saw the Oracle E-Business Suite product family contain the highest number of patches at 159, accounting for 23.6% of the total patches, followed by Oracle Fusion Middleware at 153 patches, which accounted for 22.7% of the total patches.
A full breakdown of the patches for this CSPU can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication.
| Oracle Product Family | Number of Patches | Remote Exploit without Auth |
|---|---|---|
| Oracle E-Business Suite | 159 | 19 |
| Oracle Fusion Middleware | 153 | 78 |
| Oracle Hyperion | 102 | 50 |
| Oracle Siebel CRM | 63 | 26 |
| Oracle Analytics | 50 | 8 |
| Oracle Communications | 31 | 23 |
| Oracle Commerce | 27 | 16 |
| Oracle Supply Chain | 19 | 5 |
| Oracle Virtualization | 19 | 1 |
| Oracle PeopleSoft | 16 | 4 |
| Oracle Database Server | 11 | 5 |
| Oracle Enterprise Manager | 7 | 5 |
| Oracle Financial Services Applications | 6 | 2 |
| Oracle Application Testing Suite | 3 | 0 |
| Oracle Java SE | 3 | 3 |
| Oracle Autonomous Health Framework | 2 | 1 |
| Oracle Utilities Applications | 2 | 1 |
Solution
Patches are available in the September 2026 advisory for full details.
Identifying affected systems
A list of Tenable plugins to identify these vulnerabilities will appear here as they're released. This link uses a search filter to ensure that all matching plugin coverage will appear as it is released.
Get more information
- Oracle Critical Security Patch Update Advisory - September 2026
- Oracle September 2026 Critical Security Patch Update Risk Matrices
- Oracle Advisory to CVE Map
Join