Oracle Releases Critical Patches for Fusion Middleware Vulnerabilities
Share
Oracle has released its September 2026 Critical Security Patch Update, addressing 673 vulnerabilities across 17 different product families. The update is particularly critical for users of Fusion Middleware and Oracle E-Business Suite, which account for a significant portion of the newly patched flaws.
The rollout includes five vulnerabilities within Fusion Middleware that carry a maximum CVSS score of 10.0. These critical flaws affect Oracle Access Manager (CVE-2026-71133), Oracle Forms (CVE-2026-83099), Oracle Internet Directory (CVE-2026-83059), Oracle Platform Security for Java (CVE-2026-83020), and Oracle WebLogic Server (CVE-2026-83021).
All five of these maximum-severity vulnerabilities are remotely exploitable over a network without requiring authentication, privileges, or user interaction. A sixth CVSS 10.0 vulnerability was also addressed in Oracle Hyperion Financial Management (CVE-2026-87230), which is also remotely exploitable without authentication.
High-Severity Risks in Fusion Middleware
In addition to the maximum-severity flaws, the update addresses 13 Fusion Middleware bugs with a CVSS score of 9.9. These issues affect products including Oracle WebCenter Portal, the Service Delivery Platform, and Oracle WebCenter Sites.
While these 9.9-rated vulnerabilities do not allow for remote exploitation without authentication, they remain network-accessible and require only low privileges to execute. Such flaws can result in high impacts on both data confidentiality and system integrity.
The scope of the update is broad, with Oracle E-Business Suite accounting for 159 patches and Fusion Middleware accounting for 153. Within these categories, 19 E-Business Suite vulnerabilities and 78 Fusion Middleware vulnerabilities can be exploited remotely without authentication.
Urgent Patching and Mitigation Advice
Oracle has advised customers to apply these patches immediately. The company warned that it continues to receive reports of successful attacks on its software where customers had failed to apply previously available security fixes.
This follows Oracle’s recent decision to accelerate its patching rhythm from a quarterly to a monthly cycle. Other product categories seeing significant fixes in this rollout include Oracle Database Server, Oracle Communications, and Oracle Analytics.
Until patches can be deployed, Oracle suggested that organisations may reduce their exposure by blocking the network protocols required for an attack or by removing unnecessary privileges and package access. However, the company cautioned that these measures should be tested on non-production systems first, as they risk breaking application functionality and do not address the underlying vulnerabilities.
The security fixes are provided only for versions currently under Premier or Extended Support. Organisations running older releases are not covered by these tests. Furthermore, Oracle warned that customers who have skipped previous updates should review all prior Critical Patch Updates rather than assuming the September release covers any existing backlog.




Leave a Reply