Oracle released its September edition of Critical Security Patch Update. The update received patches for 673 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
Out of the 673 security updates published, a total of 104 (15.5%) vulnerabilities are rated critical, 503 are rated as important (74.7%), and 59 are rated as medium.
In this Oracle Critical Security Patch Update, Oracle E-Business Suite received the highest number of patches, 159, constituting about 24% of the total patches released.
41 of the 673 (about 6%) security patches in the September Critical Security Patch Update are for non-Oracle CVEs, such as open-source components included in, and exploitable within, Oracle product distributions.
This batch of security patches received 13 updates for Oracle Database products. The following is the product-wise distribution:
- 11 new security updates for Oracle Database Server with a maximum reported CVSS Base Score of 8.8. 2 of these updates apply to client-only deployments of the Oracle Database.
- 2 of these updates apply to client-only deployments of the Oracle Database.
- 2 new security updates for Oracle Autonomous Health Framework with a maximum reported CVSS Base Score of 7.5.
The complete list of Oracle product families and the no of patches issued are listed below:
Qualys QID Coverage
Qualys has released the following QIDS mentioned in the table:
Note: The table will be updated with additional QIDs once released.
Notable Oracle Vulnerabilities Patched
Oracle E-Business Suite
This Critical Security Patch Update for Oracle E-Business Suite received 159 security patches. Out of these, 19 vulnerabilities can be exploited over a network without user credentials.
CVE-2026-83327, CVE-2026-83452, and CVE-2026-83462 have a critical severity rating and a CVSS score of 9.8.
Oracle Fusion Middleware
This Critical Security Patch Update for Oracle Fusion Middleware received 153 security patches. Out of these, 78 vulnerabilities can be exploited over a network without user credentials.
A total of 67 CVEs affecting various Oracle Fusion Middleware products have critical severity ratings.
Oracle Hyperion
This Critical Security Patch Update for Oracle Hyperion received 102 security patches. Out of these, 50 vulnerabilities can be exploited over a network without user credentials.
A total of 14 CVEs affecting various Oracle Hyperion products have critical severity ratings.
Oracle Siebel CRM
This Critical Security Patch Update for Oracle Siebel CRM received 63 security patches. Out of these, 26 vulnerabilities can be exploited over a network without user credentials.
CVE-2026-83197, CVE-2026-83196, CVE-2026-83201, CVE-2026-83202, CVE-2026-83229, and CVE-2026-83154 have critical severity ratings.
Oracle Analytics
This Critical Security Patch Update for Oracle Analytics received 50 security patches. Out of these, 8 vulnerabilities can be exploited over a network without user credentials.
CVE-2026-83282, CVE-2026-83269, CVE-2026-83283, and CVE-2026-83268 have critical severity ratings.








