Download Privacy Needle App

Type to search

Cybersecurity

Oracle Releases Critical Patches for Fusion Middleware Vulnerabilities

Share

Oracle has released its September 2026 Critical Security Patch Update, addressing 673 vulnerabilities across 17 different product families. The update is particularly critical for users of Fusion Middleware and Oracle E-Business Suite, which account for a significant portion of the newly patched flaws.

The rollout includes five vulnerabilities within Fusion Middleware that carry a maximum CVSS score of 10.0. These critical flaws affect Oracle Access Manager (CVE-2026-71133), Oracle Forms (CVE-2026-83099), Oracle Internet Directory (CVE-2026-83059), Oracle Platform Security for Java (CVE-2026-83020), and Oracle WebLogic Server (CVE-2026-83021).

All five of these maximum-severity vulnerabilities are remotely exploitable over a network without requiring authentication, privileges, or user interaction. A sixth CVSS 10.0 vulnerability was also addressed in Oracle Hyperion Financial Management (CVE-2026-87230), which is also remotely exploitable without authentication.

High-Severity Risks in Fusion Middleware

In addition to the maximum-severity flaws, the update addresses 13 Fusion Middleware bugs with a CVSS score of 9.9. These issues affect products including Oracle WebCenter Portal, the Service Delivery Platform, and Oracle WebCenter Sites.

While these 9.9-rated vulnerabilities do not allow for remote exploitation without authentication, they remain network-accessible and require only low privileges to execute. Such flaws can result in high impacts on both data confidentiality and system integrity.

The scope of the update is broad, with Oracle E-Business Suite accounting for 159 patches and Fusion Middleware accounting for 153. Within these categories, 19 E-Business Suite vulnerabilities and 78 Fusion Middleware vulnerabilities can be exploited remotely without authentication.

Urgent Patching and Mitigation Advice

Oracle has advised customers to apply these patches immediately. The company warned that it continues to receive reports of successful attacks on its software where customers had failed to apply previously available security fixes.

This follows Oracle’s recent decision to accelerate its patching rhythm from a quarterly to a monthly cycle. Other product categories seeing significant fixes in this rollout include Oracle Database Server, Oracle Communications, and Oracle Analytics.

Until patches can be deployed, Oracle suggested that organisations may reduce their exposure by blocking the network protocols required for an attack or by removing unnecessary privileges and package access. However, the company cautioned that these measures should be tested on non-production systems first, as they risk breaking application functionality and do not address the underlying vulnerabilities.

The security fixes are provided only for versions currently under Premier or Extended Support. Organisations running older releases are not covered by these tests. Furthermore, Oracle warned that customers who have skipped previous updates should review all prior Critical Patch Updates rather than assuming the September release covers any existing backlog.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.