Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Noodle RAT Malware Targets Windows, Linux Systems for Remote Control
September 16, 2026
Critical Fortra GoAnywhere MFT flaw lets attackers steal credentials
September 16, 2026
Oracle Q3 2023 Critical Patch Update: 673 Vulnerabilities Fixed
September 16, 2026
Home/CyberSecurity News/Oracle Q3 2023 Critical Patch Update: 673 Vulnerabilities Fixed
CyberSecurity News

Oracle Q3 2023 Critical Patch Update: 673 Vulnerabilities Fixed

Key Takeaways Oracle released an extensive Critical Security Patch Update (CSPU) in September 2026, addressing 673 distinct vulnerabilities across its product portfolio. The update included over 100...

Marcus Rodriguez
Marcus Rodriguez
September 16, 2026 3 Min Read
3 0

Key Takeaways

  • Oracle released an extensive Critical Security Patch Update (CSPU) in September 2026, addressing 673 distinct vulnerabilities across its product portfolio.
  • The update included over 100 critical-severity flaws, with more than 240 exploitable remotely without authentication.
  • Key affected product families include Oracle E-Business Suite, Fusion Middleware, and Hyperion, which account for a significant portion of the fixes, many of which are easily exploitable.
  • While no active exploitation was reported for these specific vulnerabilities, Oracle emphasized the ongoing risk from unpatched systems.

Oracle’s September Security Update Delivers Extensive Fixes

Oracle has issued one of its most comprehensive security releases to date, the September 2026 Critical Security Patch Update (CSPU). This significant bundle addresses 673 new security vulnerabilities across its enterprise software, aiming to resolve serious flaws impacting a wide range of its offerings.

Table Of Content

  • Key Takeaways
  • Oracle’s September Security Update Delivers Extensive Fixes
  • Understanding Oracle’s Patching Cadence
  • Key Product Families Affected
  • Oracle’s Warning on Unpatched Systems
  • What You Should Do

The advisory, published on September 15, encompasses 17 distinct product families. It highlights over 100 critical-severity vulnerabilities, with more than 240 flaws posing a risk of remote exploitation without requiring any authentication. This means attackers could potentially compromise systems over a network without valid credentials.

While the official count stands at 673 patches, the actual scope of remediation is even broader. Oracle’s advisory details 672 unique CVEs within its published risk matrices. However, the vendor also indicated that over 130 additional CVEs were quietly resolved through patches bundled for other vulnerabilities, pushing the effective total of remediated flaws past 800 in this single release.

This extensive update blurs the traditional distinction between Oracle’s typically lighter monthly CSPUs and its more substantial quarterly Critical Patch Updates (CPUs), a trend that has gained momentum throughout 2026.

Understanding Oracle’s Patching Cadence

The CSPU program is a relatively recent addition to Oracle’s security strategy, first introduced in May 2026. These updates are designed as targeted, high-priority releases intended for easier deployment with minimal operational disruption.

CSPUs are released on the third Tuesday of February, March, May, June, August, September, November, and December. They serve to bridge the gaps between the cumulative quarterly CPUs, which are issued each January, April, July, and October. According to the security advisory published by Oracle, this structured release schedule aims to reduce the window during which known vulnerabilities remain exploitable in customer environments. The upcoming releases include a CPU on October 20, followed by CSPUs on November 17 and December 15.

Key Product Families Affected

The Oracle E-Business Suite received the largest share of fixes, with 159 patches, 19 of which are remotely exploitable without authentication.

Oracle Fusion Middleware followed closely with 153 patches. This batch is particularly concerning, as 78 of these vulnerabilities are unauthenticated and network-exploitable, representing a significant risk, especially for internet-facing enterprise infrastructure. Hyperion ranked third, with 102 patches, half of which do not require authentication for exploitation.

Beyond these top three, Oracle also distributed substantial fixes across other product lines, including Siebel CRM (63), Analytics (50), Communications (31), Commerce (27), Supply Chain (19), Virtualization (19), and PeopleSoft (16).

Notably, the Communications update resolves over 125 additional CVEs, largely stemming from bundled third-party components, in roughly half of its patches. Other product families receiving attention include Database Server, Enterprise Manager, Financial Services Applications, Application Testing Suite, Java SE, Autonomous Health Framework, and Utilities Applications.

Oracle’s Warning on Unpatched Systems

Oracle’s advisory makes no mention of any of these specific September vulnerabilities being actively exploited in the wild. However, the company reiterated a familiar and urgent warning. Oracle continues to receive reports of attackers successfully compromising organizations that have failed to apply already available patches. This recurring pattern highlights how the delay between vulnerability disclosure and remediation often becomes an attacker’s primary entry point.

This risk is not merely theoretical. Earlier in 2026, CISA mandated federal agencies to remediate an actively exploited Oracle flaw (CVE-2026-21962, CVSS 10.0) within 72 hours, despite the patch having been available for several months prior.

What You Should Do

  • Prioritize the immediate application of these patches, especially for internet-exposed deployments of Fusion Middleware, E-Business Suite, and Hyperion, given the high volume of unauthenticated, remotely exploitable flaws.
  • Ensure all Oracle systems are running actively supported versions to guarantee access to critical security updates.
  • Consult the official September 2026 CSPU advisory for detailed patch availability documents and per-product risk matrices.
  • Regularly review and update your organization’s patch management policies to minimize the window of exposure to known vulnerabilities.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurity

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Critical Issabel PBX RCE actively exploited, patch immediately

Next Post

Critical Fortra GoAnywhere MFT flaw lets attackers steal credentials

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Apache Syncope CVEs Let Attackers Execute Code, Bypass Controls
September 16, 2026
Critical TP-Link Tapo Camera Vulnerabilities Let Attackers Spy on Users
September 16, 2026
PAPERMILL Hackers Exploit Signed Notepad++ to Deploy VenomRAT in Tax Audits
September 16, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us