Oracle's September Update Fixes Six Perfect-10 Bugs
Security / news
Oracle's September Update Fixes Six Perfect-10 Bugs
None of the maximum-severity flaws is confirmed under attack yet, but Oracle is now shipping security patches on a monthly rather than strictly quarterly calendar.

Oracle's September Critical Security Patch Update, published Sept. 15, fixes six flaws rated the maximum 10.0 on the CVSS scale, each exploitable over a network by an attacker with no credentials and no user interaction required, according to Oracle's own advisory. None of the six is confirmed under active exploitation.
The update contains 673 new patches in total across 17 product families, CSO Online reported, with 104 rated critical, arriving in the same month as Cisco's own unauthenticated, root-level flaw in Secure Email Gateway. Oracle's own advisory repeats language it has used before: that it "continues to periodically receive reports of attempts to maliciously exploit vulnerabilities for which Oracle has already released security patches," and that some of those attempts succeeded only because the target had not applied an available patch.
Where the perfect scores landed
Five of the six CVSS-10.0 flaws sit in Fusion Middleware: Oracle Access Manager (CVE-2026-71133), Oracle Forms (CVE-2026-83099), Oracle Internet Directory (CVE-2026-83059), Oracle Platform Security for Java (CVE-2026-83020) and Oracle WebLogic Server (CVE-2026-83021). The sixth, CVE-2026-87230, affects Oracle Hyperion Financial Management. A related WebLogic flaw, CVE-2026-70756, scores 9.8 rather than 10.0 and lets an unauthenticated attacker take over a server over the T3 or IIOP protocols, according to the risk matrix in Oracle's advisory.
Fusion Middleware carries the worst odds
Fusion Middleware alone accounts for 153 of the update's 673 patches, and Oracle's own risk matrix marks 78 of those as remotely exploitable without authentication, the highest count of any product family. Oracle E-Business Suite carries the second-largest patch count at 159, of which 19 need no credentials to reach over a network.
A calendar that no longer waits for the quarter
Oracle's advisory lists its next four release dates: Oct. 20 and Jan. 19 as a "CPU," the traditional quarterly Critical Patch Update, and Nov. 17 and Dec. 15 as a "CSPU," the same Critical Security Patch Update label carried by this month's release. Reading the schedule against Oracle's own naming shows the two are not the same thing renamed: Oracle has kept its quarterly Critical Patch Update on the January, April, July and October calendar it has used for years, and added a second, differently named release in the months between, so that patches now ship on the third Tuesday of every month rather than once a quarter.
- E-Business Suite159 patches
- Fusion Middleware153 patches
- Hyperion102 patches
- Analytics50 patches
Source: Oracle Critical Security Patch Update Advisory, September 2026, accessed 2026-09-21
The scoring gap between the six perfect 10s and the merely critical CVE-2026-70756, 0.2 points apart on paper but both unauthenticated and both network-reachable, echoes the same problem three Linux kernel bugs exposed on CISA's exploited-vulnerability list: a single decimal point in a CVSS score is doing less work than the label suggests once every flaw in front of it also requires no login and no click. Oracle's advisory does not explain why WebLogic's T3 flaw scored 9.8 rather than 10.0 the way its Internet Directory counterpart did.
Oracle recommends every customer running an affected product apply the September patches without delay, and its advisory points administrators to previous Critical Patch Update and Critical Security Patch Update advisories for guidance on catching up if they skipped an earlier one.
Sources
More in Security
- 01WordPress 7.1.1 Closes the Click2Shell Remote Code ChainResearcher Paulos Yibelo's chain turned one clicked link into server-side code execution by tricking WordPress into silently installing a theme with no authorization checks at all.
- 02Mathspace Breach Exposes Data on 1.08 Million StudentsAttackers had 17 days between reaching Mathspace's reporting database and downloading it, and the company patched the underlying Metabase flaw only after both had happened.
- 03BragJack Hijacks AI Agents Built Into Five BrowsersA single malicious extension could seize Chrome's Gemini, Edge's Copilot, Opera Neon, Perplexity Comet and Claude in Chrome without bypassing any model's guardrails or writing a single injected prompt.
- 04Two Days After a Patch, Red Heron Scanned 1,386 Gitea ServersAcronis says the Chinese-speaking group turned a fixed Gitea flaw into a rootkit-based campaign that compromised organizations in five countries within a week.