Oracle’s September patches put Fusion Middleware back in the hot seat
VulnOracle’s September 2026 Critical Security Patch Update has arrived with 673 new security patches spanning 17 Oracle product families, with Oracle E-Business Suite accounting for the largest share at 159 patches, followed by Fusion Middleware with 153. Of these, 19 E-Business Suite vulnerabilities and 78 Fusion Middleware vulnerabilities can be remotely exploited without authentication. Other product categories with 50 or more issues fixed in the rollout include Oracle Database Server, Oracle Communications, and Oracle Analytics. Oracle recently accelerated its patching rhythm from quarterly to monthly. It advised customers to apply the September patches immediately, warning that it continues to receive reports of successful attacks on its software where customers had not applied available fixes. Five max-severity flaws sit in Fusion Middleware The September update addresses five critical vulnerabilities carrying the maximum CVSS score of 10.0 within Fusion Middleware. They affect Oracle Access Manager (CVE-2026-71133), Oracle Forms (CVE-2026-83099), Oracle Internet Directory (CVE-2026-83059), Oracle Platform Security for Java (CVE-2026-83020), and Oracle WebLogic Server (CVE-2026-83021). All five are remotely exploitable without authentication over the network; attacking them is of low complexity and requires neither privileges nor user interaction. The update also addressed a sixth CVSS 10.0 vulnerability, this one in Oracle Hyperion Financial Management (CVE-2026-87230); it too can be remotely exploited without authentication. The update also includes 13 Fusion Middleware bugs with a CVSS score of 9.9, just below the maximum severity. These include CVE-2026-71163 and CVE-2026-73945 in Oracle Access Manager, CVE-2026-83055, CVE-2026-83057 and CVE-2026-83056 in Oracle Internet Directory, CVE-2026-83058, CVE-2026-73948 and CVE-2026-83039 in Oracle WebCenter Portal, CVE-2026-82999, CVE-2026-82997 and CVE-2026-82998 in Service Delivery Platform, and one each in Oracle WebCenter Sites (CVE-2026-83031) and Oracle WebLogic Server (CVE-2026-83038). None of these are remotely exploitable without authentication. However, they require low privileges, remain network-accessible and can have high confidentiality and integrity impacts. Oracle did not mark any of the six CVSS 10.0 and 13 CVSS 9.9 vulnerabilities as exploited in the wild. Fusion Middleware has featured heavily in Oracle’s recent patch cycles too. Its July update addressed 10 CVSS 10.0 vulnerabilities, highlighting the product family’s recurring exposure to maximum-severity flaws. Oracle’s patching message is as important as the patches Until patches can be deployed, Oracle said, customers may reduce exposure by blocking network protocols required for an attack or removing unnecessary privileges and package access. However, it cautioned, these measures can break application functionality and should be tested on non-production systems. They are not to be considered long-term solutions because they do not address the underlying vulnerabilities, the company said in its September critical patch update advisory. It also included a warning for organizations running older Oracle releases. The fixes are provided only for supported versions, the company said, adding that “Product releases that are not under Premier Support or Extended Support are not tested for the presence of vulnerabilities addressed by this Critical Security Patch Update.” Also, for organizations that have skipped earlier security updates, Oracle advises reviewing previous CSPUs and quarterly Critical Patch Updates rather than assuming the September releases covers the backlog. This article first appeared on CIO.
Read full story at CSO Online →