Summary
- Oracle’s September 2026 Critical Security Patch Update contains 673 new security patches.
- Major affected families include E-Business Suite, Fusion Middleware, Hyperion, Siebel, databases, enterprise management, and Java.
- Large Oracle estates face a prioritisation problem because many fixes affect interdependent and business-critical systems.
Oracle has released 673 new security patches across a broad range of enterprise products, creating a substantial remediation exercise for organisations running its databases, middleware, business applications, analytics, and infrastructure software.
The September release is a Critical Security Patch Update, or CSPU, rather than Oracle’s quarterly cumulative Critical Patch Update. Oracle introduced the more focused CSPU programme to deliver high-priority fixes between quarterly releases.
The September advisory covers product families including Oracle Database, E-Business Suite, Fusion Middleware, Hyperion, Enterprise Manager, PeopleSoft, Siebel CRM, Communications, Supply Chain, Analytics, and Java-related technology.
The figure of 673 refers to new security patches, not 673 unique vulnerabilities. Some vulnerabilities affect more than one product and can appear in multiple risk matrices, while individual patches can address multiple CVEs.
Oracle’s E-Business Suite alone receives 159 new patches in the release, while Fusion Middleware receives 153 and Hyperion 102. Dozens of vulnerabilities across those families may be remotely exploitable without authentication.
Several flaws carry scores at or near the top of the CVSS scale. Oracle Hyperion Financial Management includes a vulnerability rated 10.0, while critical 9.8 issues appear across Communications, Enterprise Manager, and other products.
The operational problem is larger than the number of fixes. Oracle technology often supports finance, human resources, identity, billing, supply chain, customer management, databases, and middleware that connect multiple business applications.
Updating those systems can require dependency checks, compatibility testing, maintenance windows, and coordination between infrastructure and application owners.
Legacy environments can make that work harder. Enterprise applications may remain in service for years because customisation, business-process dependencies, and migration costs make major upgrades difficult.
Oracle says CSPU patches are provided for releases covered by Premier Support or Extended Support and warns that older versions may also be affected even where fixes have not been tested against them.
The company also repeats a longstanding warning that attackers have successfully exploited vulnerabilities for which fixes were already available because targeted customers had not applied earlier patches.
That makes prioritisation central to the September release. Remediation order can depend on whether a system is internet-facing, whether exploitation is possible without authentication, the privileges an attacker could obtain, the business importance of the service, and whether compensating controls are available.
A flat programme treating all 673 patches as equivalent would obscure those differences. Large estates need to map the advisory against the versions and components they actually operate before identifying the exposures carrying the greatest operational consequence.
Asset visibility remains the starting point. Oracle components may be present inside finance systems, inherited environments, middleware stacks, and acquired applications long after the original implementation teams have changed.
The September CSPU therefore presents two linked problems: applying a substantial volume of fixes and knowing where those fixes are required. Oracle has published the remediation detail; the harder enterprise task is connecting that information to a current inventory and a change process capable of moving the highest-risk systems first.




