# Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

DevFeed: [Oracle September 2026 Critical Security Patch Update addresses 672 CVEs](<https://devfeed.tech/articles/oracle-september-2026-critical-security-patch-update-addresses-672-cves-26926.md>)

Original publisher: [Read original article](<https://www.tenable.com/blog/oracle-september-2026-critical-security-patch-update-addresses-672-cves>)

Author: Research Special Operations

Published: 2026-09-15T21:00:28Z

Content type: article

Language: en

Sources: [Tenable Blog](<https://devfeed.tech/sources/tenable-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Network](<https://devfeed.tech/topics/network.md>)

Tags: [cves](<https://devfeed.tech/tags/cves.md>), [network](<https://devfeed.tech/tags/network.md>), [security](<https://devfeed.tech/tags/security.md>), [september-2026](<https://devfeed.tech/tags/september-2026.md>), [update](<https://devfeed.tech/tags/update.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

## AI overview

Oracle's September 2026 Critical Security Patch Update fixes 672 unique CVEs through 673 security updates across 17 Oracle product families. It includes 104 critical patches, with Oracle E-Business Suite receiving the most patches.

## Source excerpt

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at 159, accounting for 23.6% of all patches Background On September 15, Oracle released its Critical Security Patch Update (CSPU) for September 2026. Beginning in May 2026, Oracle introduced CSPUs as a monthly release cycle that sits between the larger quarterly Critical Patch Updates (CPUs), addressing a focused set of high-severity issues on a faster cadence. This CSPU contains fixes for 672 unique CVEs in 673 security updates across 17 Oracle product families. Out of the 673 security updates published, 15.5% of patches were assigned a critical severity. High severity patches accounted for the bulk of security patches at 74.7%, followed by critical severity patches at 15.5%. This month's update includes 104 critical patches across 104 CVEs. SeverityIssues PatchedCVEsCritical104104High503503Medium5958Low77Total673672 Analysis This month's update saw the Oracle E-Business Suite product family contain the highest number of patches at 159, accounting for 23.6% of the total patches, followed by Oracle Fusion Middleware at 153 patches, which accounted for 22.7% of the total patches. A full breakdown of the patches for this CSPU can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication. Oracle Product FamilyNumber of PatchesRemote Exploit without AuthOracle E-Business Suite15919Oracle Fusion Middleware15378Oracle Hyperion10250Oracle Siebel CRM6326Oracle Analytics508Oracle Communications3123Oracle Commerce2716Oracle Supply Chain195Oracle Virtualization191Oracle PeopleSoft164Oracle Database Server115