Dev48
Language
  • About
  • Services
  • Industries
  • Technologies
  • Articles
  • Contacts
Book a call
    Home/Articles/Oracle critical security patch update september 2026 review
Dev48

© 2026 · All rights reserved.

Oracle Critical Security Patch Update, September 2026 Review

Источник: Qualys

Oracle Critical Security Patch Update, September 2026 Review

Source: Qualys

Oracle released its September edition of Critical Security Patch Update. The update received patches for 673 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.  Out of the 673 security updates published, a total

September 25, 2026

Oracle released its September edition of Critical Security Patch Update. The update received patches for 673 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.

Out of the 673 security updates published, a total of 104 (15.5%) vulnerabilities are rated critical, 503 are rated as important (74.7%), and 59 are rated as medium.

In this Oracle Critical Security Patch Update, Oracle E-Business Suite received the highest number of patches, 159, constituting about 24% of the total patches released.

41 of the 673 (about 6%) security patches in the September Critical Security Patch Update are for non-Oracle CVEs, such as open-source components included in, and exploitable within, Oracle product distributions.

This batch of security patches received 13 updates for Oracle Database products. The following is the product-wise distribution:

  • 11 new security updates for Oracle Database Server with a maximum reported CVSS Base Score of 8.8. 2 of these updates apply to client-only deployments of the Oracle Database.
  • 2 of these updates apply to client-only deployments of the Oracle Database.
  • 2 new security updates for Oracle Autonomous Health Framework with a maximum reported CVSS Base Score of 7.5.

The complete list of Oracle product families and the no of patches issued are listed below:

Qualys QID Coverage

Qualys has released the following QIDS mentioned in the table:

Note: The table will be updated with additional QIDs once released.

Notable Oracle Vulnerabilities Patched

Oracle E-Business Suite

This Critical Security Patch Update for Oracle E-Business Suite received 159 security patches. Out of these, 19 vulnerabilities can be exploited over a network without user credentials.

CVE-2026-83327, CVE-2026-83452, and CVE-2026-83462 have a critical severity rating and a CVSS score of 9.8.

Oracle Fusion Middleware

This Critical Security Patch Update for Oracle Fusion Middleware received 153 security patches. Out of these, 78 vulnerabilities can be exploited over a network without user credentials.

A total of 67 CVEs affecting various Oracle Fusion Middleware products have critical severity ratings.

Oracle Hyperion

This Critical Security Patch Update for Oracle Hyperion received 102 security patches. Out of these, 50 vulnerabilities can be exploited over a network without user credentials.

A total of 14 CVEs affecting various Oracle Hyperion products have critical severity ratings.

Oracle Siebel CRM

This Critical Security Patch Update for Oracle Siebel CRM received 63 security patches. Out of these, 26 vulnerabilities can be exploited over a network without user credentials.

CVE-2026-83197, CVE-2026-83196, CVE-2026-83201, CVE-2026-83202, CVE-2026-83229, and CVE-2026-83154 have critical severity ratings.

Oracle Analytics

This Critical Security Patch Update for Oracle Analytics received 50 security patches. Out of these, 8 vulnerabilities can be exploited over a network without user credentials.

CVE-2026-83282, CVE-2026-83269, CVE-2026-83283, and CVE-2026-83268 have critical severity ratings.

← All articles

More in Cybersecurity

All →
Protéger votre téléviseur connecté et votre boîtier contre le piratage
Kaspersky

Protéger votre téléviseur connecté et votre boîtier contre le piratage

Key source of economic growth in Canada may be overlooked, new research reveals
PwC

Key source of economic growth in Canada may be overlooked, new research reveals

Building trust and governance as agentic AI scales
PwC

Building trust and governance as agentic AI scales

A Decision Model Breaks Like Any Other Language Model: A First Look at Jev
Check Point

A Decision Model Breaks Like Any Other Language Model: A First Look at Jev

Can We Control Every AI Agent Before It Becomes Our Next Privileged Insider?
Check Point

Can We Control Every AI Agent Before It Becomes Our Next Privileged Insider?

CISA BOD 26-04 Timelines for Three Linux Kernel CVEs
Qualys

CISA BOD 26-04 Timelines for Three Linux Kernel CVEs

More from Qualys

CISA BOD 26-04 Timelines for Three Linux Kernel CVEs
Qualys

CISA BOD 26-04 Timelines for Three Linux Kernel CVEs

The End of Point-in-Time Compliance: Why Continuous Audit Readiness Matters to You in the AI Era
Qualys

The End of Point-in-Time Compliance: Why Continuous Audit Readiness Matters to You in the AI Era

The Autonomous Engine Behind Remediation, and What Finally Makes It Safe
Qualys

The Autonomous Engine Behind Remediation, and What Finally Makes It Safe

Before You Patch. Why Patch Reliability Matters for Confident Deployment
Qualys

Before You Patch. Why Patch Reliability Matters for Confident Deployment