Bottom line: Oracle's September 2026 Critical Security Patch Update poses significant risks to Fusion Middleware installations, particularly those without timely patching.
What's happening: Oracle released 673 new security patches in September 2026, with 17 Oracle product families affected, including E-Business Suite (159 patches), Fusion Middleware (153 patches), and WebLogic Server (44 patches). The 19 vulnerabilities in Oracle E-Business Suite and 23 in Oracle WebLogic Server have CVSS scores of 9.3 and 9.5, respectively.
What to do: Security teams should prioritize patching Fusion Middleware and other affected products to minimize the risk of exploitation, and consider implementing a vulnerability management program to ensure timely updates. END OF BRIEFING