Oracle’s September patches put Fusion Middleware back in the hot seat

Summary

Oracle has released its September 2026 Critical Security Patch Update, addressing 673 vulnerabilities across 17 product families. Notably, Fusion Middleware has 153 patches, including 78 that can be exploited remotely without authentication. Five of these Fusion Middleware vulnerabilities carry a maximum CVSS score of 10.0.

IFF Assessment

FOE

The article details numerous critical vulnerabilities, including several with the highest CVSS score, that are exploitable remotely without authentication, posing a significant risk to organizations running Oracle products.

Severity

10.0 Critical

Defender Context

Defenders should prioritize patching Oracle products, especially Fusion Middleware, E-Business Suite, and Database Server, as Oracle has observed ongoing attacks against unpatched systems. The presence of multiple remotely exploitable, high-severity vulnerabilities necessitates immediate attention to mitigate significant risks.

Read Full Story →