Oracle’s September patches put Fusion Middleware back in the hot seat
Summary
Oracle has released its September 2026 Critical Security Patch Update, addressing 673 vulnerabilities across 17 product families. Notably, Fusion Middleware has 153 patches, including 78 that can be exploited remotely without authentication. Five of these Fusion Middleware vulnerabilities carry a maximum CVSS score of 10.0.
IFF Assessment
The article details numerous critical vulnerabilities, including several with the highest CVSS score, that are exploitable remotely without authentication, posing a significant risk to organizations running Oracle products.
Severity
Defender Context
Defenders should prioritize patching Oracle products, especially Fusion Middleware, E-Business Suite, and Database Server, as Oracle has observed ongoing attacks against unpatched systems. The presence of multiple remotely exploitable, high-severity vulnerabilities necessitates immediate attention to mitigate significant risks.