Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070
2-minute read Sep 15 2026

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

A header image for tenable research special operations on a dark background. The central text reads Oracle Critical Security Patch Update (CSPU) in white and blue lettering, with September 2026 written below. The design features a white hexagonal logo in the center and an abstract pattern of white hexagons along the right edge.

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates.

Key Takeaways

  1. The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates
  2. 104 issues (15.5% of all patches) were assigned a critical severity rating
  3. Oracle E-Business Suite received the highest number of patches at 159, accounting for 23.6% of all patches

Background

On September 15, Oracle released its Critical Security Patch Update (CSPU) for September 2026. Beginning in May 2026, Oracle introduced CSPUs as a monthly release cycle that sits between the larger quarterly Critical Patch Updates (CPUs), addressing a focused set of high-severity issues on a faster cadence. This CSPU contains fixes for 672 unique CVEs in 673 security updates across 17 Oracle product families. Out of the 673 security updates published, 15.5% of patches were assigned a critical severity. High severity patches accounted for the bulk of security patches at 74.7%, followed by critical severity patches at 15.5%.

Pie chart showing the count of patches released in the Oracle September 2026 Critical Security Patch Update (CSPU)

This month's update includes 104 critical patches across 104 CVEs.

SeverityIssues PatchedCVEs
Critical104104
High503503
Medium5958
Low77
Total673672

Analysis

This month's update saw the Oracle E-Business Suite product family contain the highest number of patches at 159, accounting for 23.6% of the total patches, followed by Oracle Fusion Middleware at 153 patches, which accounted for 22.7% of the total patches.

A full breakdown of the patches for this CSPU can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication.

Oracle Product FamilyNumber of PatchesRemote Exploit without Auth
Oracle E-Business Suite15919
Oracle Fusion Middleware15378
Oracle Hyperion10250
Oracle Siebel CRM6326
Oracle Analytics508
Oracle Communications3123
Oracle Commerce2716
Oracle Supply Chain195
Oracle Virtualization191
Oracle PeopleSoft164
Oracle Database Server115
Oracle Enterprise Manager75
Oracle Financial Services Applications62
Oracle Application Testing Suite30
Oracle Java SE33
Oracle Autonomous Health Framework21
Oracle Utilities Applications21

Solution

Patches are available in the September 2026 advisory for full details.

Identifying affected systems

A list of Tenable plugins to identify these vulnerabilities will appear here as they're released. This link uses a search filter to ensure that all matching plugin coverage will appear as it is released.

Get more information

Join Tenable's Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.

Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.

Author

Learn more