Summary
Oracle's September 2026 Critical Security Patch Update delivers 673 fixes across its product line, including roughly 65 critical-severity flaws scored 9.0 or higher and six maximum-severity (CVSS 10.0) bugs. Five of them are in Fusion Middleware components like Access Manager, WebLogic, Forms Services, and Internet Directory, all remotely exploitable without authentication or user interaction.
Take Action:
If you are using Oracle products, review this advisory in detail. Prioritize patching of internet-facing systems, as 247 of the vulnerabilities allow remote attackers to compromise your systems without any authentication. Patch Oracle Fusion Middleware first: it accounts for five of the six flaws scored CVSS 10.0 and 78 network-accessible vulnerabilities requiring no credentials. Oracle Hyperion should follow, where 50 of 102 patches address unauthenticated remote issues and a sixth CVSS 10.0 flaw sits in Hyperion Financial Management.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)