Oracle patches over 800 vulnerabilities in September 2026 update
Summary
Oracle announced the release of its September 2026 Critical Security Patch Update (CSPU), addressing over 800 vulnerabilities through 673 new security patches. The update includes 672 unique CVEs and remedies critical-severity flaws, with more than 240 vulnerabilities being remotely exploitable without authentication. Among the products receiving significant updates are the Oracle E-Business Suite, Fusion Middleware, and Hyperion. Despite no mention of existing exploits in the wild, Oracle emphasizes the importance of promptly applying these patches, noting that past failures to do so have led to successful attacks on consumers' systems. This reflects a trend among major software vendors to prioritize the timely release of large-scale security updates to safeguard enterprise environments.