Oracle Fixes More Than 800 Security Flaws in Its Biggest Patch Drop of 2026
Oracle's September 2026 Critical Security Update bundles 673 patches covering over 800 vulnerabilities. More than 240 of those flaws can be exploited remotely by anyone, no password required.

Key points
- Oracle released 673 security patches in its September 2026 Critical Patch Update, resolving more than 800 individual vulnerabilities across its product line.
- Over 240 of the fixed flaws were remotely exploitable without login credentials, meaning an attacker anywhere on the internet could have used them.
- Oracle E-Business Suite received the largest single batch: 159 patches, 19 covering flaws open to unauthenticated remote attack.
- Oracle confirmed none of the vulnerabilities are known to be actively exploited, but warned that real-world attacks on unpatched Oracle systems are a regular occurrence.
- Fusion Middleware, Hyperion, Siebel CRM, Java SE, and Analytics were among the other products updated in the same release.
Oracle normally ships patches in January, April, July, and October. September 2026 breaks that rhythm. The numbers are large even by Oracle standards.
673 new patches. More than 800 vulnerabilities resolved. Over 100 rated critical severity, meaning the kind of flaw that gives an attacker full control of a system. That last figure is the one defenders should focus on. Less than a month ago we covered Oracle's August release, which closed more than 1,000 flaws including nearly 90 bugs scoring 9.8 or higher on the 0-to-10 severity scale. Back-to-back releases of this size are not routine.
Which products were hit hardest?
Oracle E-Business Suite, a platform businesses use to manage finances and HR records, received the most patches: 159 in total. Fusion Middleware, software that connects different Oracle applications, was close behind with 153 patches, including fixes for 78 flaws that required no login to exploit.
| Product | Patches | Unauthenticated remote flaws |
|---|---|---|
| E-Business Suite | 159 | 19 |
| Fusion Middleware | 153 | 78 |
| Hyperion | 102 | 50 |
| Siebel CRM | 63 | not specified |
| Analytics | 50 | not specified |
| Communications | 31 | resolves 125+ additional CVEs |
The Communications product deserves a specific note. Half of its 31 patches quietly resolved more than 125 additional CVEs (Common Vulnerabilities and Exposures, the standard numbered labels assigned to known security flaws). That is a lot of cleanup bundled inside a modest patch count.
Database Server, Java SE, PeopleSoft, Financial Services Applications, and Enterprise Manager were also updated, which means the patch covers infrastructure used by banks, hospitals, universities, and government agencies.
Should ordinary people be worried about this?
Not directly, but the indirect exposure is real. You probably don't run Oracle software at home. Your employer or health system almost certainly does.
Oracle says it has no evidence these specific flaws are being exploited right now. But the company was direct in its advisory: attackers routinely target Oracle products, and victims are usually organisations that delayed applying patches Oracle had already shipped. "Oracle therefore strongly recommends that customers remain on actively-supported versions and apply security patches without delay," the company stated.
If your organisation runs Oracle systems, the practical step is straightforward: ask your IT team whether the September 2026 Critical Patch Update has been applied and, if not, get a timeline.
A single unpatched flaw in a system like E-Business Suite can hand attackers access to payroll records, customer data, or financial accounts. More than 240 flaws open to anyone with an internet connection is not a theoretical risk; it is an open door that needs closing now.
Oracle's full September 2026 Critical Patch Update advisory carries the complete product-by-product breakdown.



