News

Urgent action recommended · active exploitation confirmed

September CSPU: Patch Volume Drops Sharply, but Six Vulnerabilities Reach Maximum Severity

Summary and analysis of the September Critical Security Patch Update (CSPU)

Key findings, Oracle CSPU September 2026

Highlights

The September 2026 Critical Security Patch Update includes 673 new security patches across 17 product families. As in prior CSPUs, a single vulnerability can appear in more than one risk matrix when it affects several products. Highlights include:

  • 673 new security patches, down from the record 943 in August and well above June’s 245. September is the second largest CSPU Oracle has issued, a decline of close to 29 percent from August, and the first month-over-month drop since the CSPU program began on 28 May 2026.
  • 247 of the 673 patches, a little over a third of the release, address vulnerabilities Oracle classifies as remotely exploitable without authentication. That share is down from just under half in August, though the absolute count of unauthenticated issues remains substantial.
  • Six vulnerabilities carry the maximum CVSS base score of 10.0 this month, and all six require no authentication. Five sit in Oracle Fusion Middleware: Oracle Access Manager’s Authentication Engine (CVE-2026-71133), Oracle Forms (CVE-2026-83099), Oracle Internet Directory’s OID LDAP Server (CVE-2026-83059), Oracle Platform Security for Java (CVE-2026-83020), and Oracle WebLogic Server’s Web Container (CVE-2026-83021). The sixth, CVE-2026-87230, sits in Oracle Hyperion Financial Management’s Security component.
  • Fusion Middleware receives 153 patches, 78 of them unauthenticated, including the five 10.0s above, 13 further entries at 9.9 (all requiring authentication), and at least 32 more unauthenticated entries at 9.8, spanning WebLogic Server, Access Manager, Internet Directory, Identity Manager, Oracle Forms, Data Integrator, WebCenter and several further products.
  • Hyperion receives 102 patches, 50 unauthenticated, concentrated almost entirely in Hyperion Financial Management’s Security component, with a smaller cluster in Data Relationship Management.
  • E-Business Suite is the single largest product family this month at 159 patches, though only 19 are unauthenticated and its ceiling is 9.8 rather than 10.0, across versions 12.2.3 through 12.2.15.
  • PeopleSoft and Java SE are comparatively light this month. PeopleSoft receives 16 patches with a ceiling of 8.8, the first time in recent CSPUs it has had no entry at or above 9.0, and Java SE receives 3 patches, all in the GraalVM Compiler component, all unauthenticated, with a ceiling of 8.1.
  • No vulnerability first disclosed in the September CSPU has been publicly confirmed as under active exploitation as of publication.

The practical threat picture continues to be shaped by previously disclosed Oracle flaws in products covered by this release: four are confirmed exploited, including one added to the CISA Known Exploited Vulnerabilities catalog barely three weeks before this release.

Patch volume by product family

Product familyPatchesRemote, no authHighest CVSS
Oracle E-Business Suite159199.8
Oracle Fusion Middleware1537810.0
Oracle Hyperion1025010.0
Oracle Siebel CRM63269.1
Oracle Analytics5089.9
Oracle Communications31239.8
Oracle Commerce27168.2
Oracle Supply Chain1959.8
Oracle Virtualization (VirtualBox)1918.6
Oracle PeopleSoft1648.8
Oracle Database Server1158.8
Oracle Enterprise Manager759.8
Oracle Financial Services Applications628.0
Oracle Application Testing Suite309.1
Oracle Java SE338.1
Oracle Autonomous Health Framework217.5
Oracle Utilities Applications218.2
Total67324710.0

Source: Oracle Critical Security Patch Update Advisory, September 2026, published 15 September 2026. Counts are new security patches, not unique CVEs.

Family level analysis

Oracle Fusion Middleware

Fusion Middleware carries 153 patches this month, 78 of them unauthenticated, a lighter release than August’s 262 but home to five of this release’s six maximum-severity findings. All five score a full 10.0 and all five require no authentication: CVE-2026-71133 in Oracle Access Manager’s Authentication Engine over HTTP, CVE-2026-83099 in Oracle Forms’ Services, C/S and Charmode component over HTTP, CVE-2026-83059 in Oracle Internet Directory’s OID LDAP Server over LDAP, CVE-2026-83020 in Oracle Platform Security for Java’s Centralized Thirdparty Jars over HTTP, and CVE-2026-83021 in Oracle WebLogic Server’s Web Container over HTTP.

Identity and directory infrastructure, the same category behind August’s Internet Directory 10.0 and multiple Identity Manager 9.8 findings, is disproportionately represented again. Internet Directory alone contributes the 10.0 above plus four further unauthenticated 9.9s and five further unauthenticated 9.8s, all in the same OID LDAP Server component. WebLogic Server adds three more unauthenticated 9.8s in its Core component over T3 and IIOP, CVE-2026-70756, CVE-2026-70757 and CVE-2026-70748, the same deserialization-prone channels behind past WebLogic remote code execution campaigns.

Separately from this month’s new disclosures, WebLogic Server’s HTTP proxy plug-in carries the release period’s most consequential confirmed risk. CVE-2026-21962, an improper access control flaw in the WebLogic Server Proxy Plug-in for Apache HTTP Server and for Microsoft IIS, was patched in the January 2026 Critical Patch Update but was added to the CISA Known Exploited Vulnerabilities catalog on 24 August 2026 after a mass exploitation campaign. Any WebLogic deployment fronted by the Apache or IIS proxy plug-in should have this patch independently verified regardless of this month’s new findings; see the active exploitation section below.

Oracle E-Business Suite

E-Business Suite is the largest single product family in this release at 159 patches, though only 19 are unauthenticated and the ceiling is 9.8, across versions 12.2.3 through 12.2.15. Three new entries reach that ceiling, and all three are unauthenticated: CVE-2026-83327 in Oracle Applications Framework’s Personalization component over SOAP, CVE-2026-83452 in Oracle Document Management and Collaboration’s Internal Operations component over HTTP, and CVE-2026-83462 in the Oracle Mobile Application Server’s MWA Terminal Server component over TCP. The remainder of the published matrix is a broad sweep of authenticated 8.8-and-lower findings across Applications Manager, Bills of Material, Purchasing, Product Hub, Contracts and dozens of further modules, consistent with EBS’s usual pattern of many lower-privilege, module-specific issues alongside a smaller number of unauthenticated critical ones.

The component to watch remains Oracle Payments, even though none of this month’s new EBS entries touch it. CVE-2026-46817, an unauthenticated 9.8 in the File Transmission component, was fixed in the May 2026 CSPU, observed under exploitation from late June, and added to the CISA Known Exploited Vulnerabilities catalog on 15 July with a three-day federal remediation deadline. Any EBS estate that has not independently confirmed that patch is applied should treat it as the priority ahead of this month’s new EBS entries.

Oracle PeopleSoft

PeopleSoft is a comparatively light month: 16 patches, 4 unauthenticated, with a ceiling of 8.8, the first time in recent CSPUs that the family has had no entry at or above 9.0. The highest entry, CVE-2026-83017 in PeopleTools’ Report Distribution component, requires authentication. Of the four unauthenticated entries, the one to note is CVE-2026-73954, an 8.1 in the Business Interlink component over HTTP, the same integration point that carried a 9.8 in August. The other three are lower severity: CVE-2026-25639 in the CC Common Application Objects Chatbot Framework (Axios) at 7.5, CVE-2026-73960 in PeopleTools’ Ren Server at 7.5, and CVE-2026-7598, a third-party libssh2 flaw in PeopleTools’ File Processing component, at 7.3. Coverage spans PeopleTools 8.61 through 8.63 alongside the FIN Inventory Brazil, FIN Engineering Brazil, CC Common Application Objects and PRTL Interaction Hub modules.

The modest patch count should not be read as reduced risk for this platform. PeopleSoft remains the Oracle product family with the most credible current threat, because it is the platform under sustained, named adversary attention. CVE-2026-35273, an unauthenticated server-side request forgery in the Updates Environment Management component chained to remote code execution, was exploited as a zero day from 27 May through 9 June 2026 by the group tracked as UNC6240 and publicly known as ShinyHunters, with more than 100 organizations notified, most of them in higher education.

CVE-2026-35278, a pre-authentication remote code execution in the Performance Monitor and Environment Management Hub components, was chained with it by the same actor. Both were addressed in Oracle’s June out-of-band alert and folded into the July CPU, and CISA addressed CVE-2026-35273 under Binding Operational Directive 26-04. Any PeopleSoft instance that was internet facing and unpatched during the exposure window warrants a compromise investigation regardless of current patch level, since a later patch does not remove an attacker who already gained a foothold.

Oracle Java SE

Java SE is the lightest family in this release: 3 patches, all 3 unauthenticated, all three in the Compiler component of Oracle GraalVM, with a ceiling of 8.1. CVE-2026-83357 and CVE-2026-83408 each score 8.1 in Oracle GraalVM for JDK; CVE-2026-83368, shared with Oracle GraalVM Enterprise Edition, scores 7.0.

Notably, nothing this month touches the core JDK release lines directly, only the GraalVM distributions, and none of the three approaches the critical band. The structural point from prior CSPUs still holds, though: Fusion Middleware, WebLogic, Hyperion, PeopleTools and E-Business Suite all execute on the Java Virtual Machine, so the runtime remains the execution layer beneath this release’s genuinely critical findings even in a quiet month for the Java SE matrix itself.

Vulnerabilities under active exploitation

As of publication, no vulnerability first disclosed in the September CSPU has been publicly confirmed as exploited in the wild. Four previously disclosed flaws in products covered by this release remain the practical threat picture, and the most recent of them was added to CISA’s Known Exploited Vulnerabilities catalog barely three weeks before this release.

CVE-2026-21962, Oracle Fusion Middleware, WebLogic Server Proxy Plug-in, CVSS 10.0

An improper access control flaw in the WebLogic Server Proxy Plug-in for Apache HTTP Server and for Microsoft IIS, versions 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0, that lets an unauthenticated attacker with network access bypass access controls using specially crafted HTTP requests. Oracle fixed it in the January 2026 Critical Patch Update.

Proof-of-concept code appeared within roughly 48 hours of disclosure, and honeypot telemetry recorded close to 140,000 attack attempts across 21 countries between late January and early February, about three quarters of them aimed at United States based systems. CISA added the CVE to its Known Exploited Vulnerabilities catalog on 24 August 2026 with a short federal remediation deadline.

Any deployment that has not independently verified this patch, particularly one still running the proxy plug-in in front of Apache or IIS, should treat it as an immediate priority independent of this month’s new disclosures.

CVE-2026-35273, PeopleSoft Enterprise PeopleTools, CVSS 9.8

An unauthenticated flaw in the Updates Environment Management component, classified as server-side request forgery and chained to remote code execution. Exploitation ran from 27 May through 9 June 2026, ahead of Oracle’s out-of-band alert on 10 June, making it a true zero day for the duration of the campaign. Reporting attributes it to the ShinyHunters extortion group, tracked as UNC6240, with more than 100 organizations notified, roughly two thirds of them in higher education. CISA addressed it under Binding Operational Directive 26-04.

CVE-2026-35278, PeopleSoft Enterprise PeopleTools, CVSS 9.8

A pre-authentication remote code execution vulnerability in the Performance Monitor and Environment Management Hub components, chained with CVE-2026-35273 by the same actor in the same campaign. The full fix shipped in the July 2026 CPU.

CVE-2026-46817, Oracle E-Business Suite, CVSS 9.8

An improper privilege management flaw in the File Transmission component of Oracle Payments, allowing an unauthenticated attacker with HTTP access to take over the component. Fixed in the May 2026 CSPU, observed under exploitation from 29 June, and added to the CISA Known Exploited Vulnerabilities catalog on 15 July with a three-day remediation deadline. This month’s EBS matrix contains further unauthenticated entries in adjacent components, so File Transmission remains the one to confirm first.

The pattern across all four is consistent. In every case the exploitation activity either preceded the patch or continued well after it shipped, and in the WebLogic case the KEV listing arrived seven months after the fix was available. A patch that exists but has not cleared regression testing provides no protection, and neither does one applied to a system that was already compromised during the exposure window.

Waratek recommends a defense-in-depth posture for these attack chains, so that there are multiple points at which an attack can be intercepted rather than a single dependency on patch availability and deployment speed. Waratek customers who need assistance identifying or enabling the relevant controls should contact our Customer Success team.

How Waratek addresses the risk

Waratek RASP operates inside the Java Virtual Machine rather than at the network perimeter. Because it enforces on what the application is actually doing at runtime, it addresses classes of unsafe behavior including deserialization of untrusted data, server-side request forgery, path traversal, command injection, JNDI and LDAP lookups, SQL injection and XML external entity processing, independent of which specific CVE number is behind the behavior.

That distinction matters for both halves of this month’s disclosure pipeline. Oracle attributes a growing share of its own vulnerability discovery to AI-assisted identification of security findings, a trend visible in the record volume of the last two CSPUs. The same class of tooling that lets Oracle surface hundreds of issues a month is available to attackers for discovery, triage and exploit development, and the CVE-2026-21962 WebLogic proxy campaign showed how quickly a patched flaw can be weaponized at scale once proof-of-concept code is public. Coverage organized around behavior, rather than around a specific CVE identifier, applies equally to a vulnerability an automated discovery pipeline surfaced last month, one a human researcher reports tomorrow, and one that has not been disclosed to anyone yet, including a true zero day of the kind that hit PeopleSoft in May.

Preemptive Security rules and patching together supply the one thing the current release cadence removes, which is time. Waratek applies compensating controls with no source code changes, no recompilation and no downtime, so exposure can be reduced the day an advisory lands while regression testing and vendor patching proceed on a schedule the business can absorb.

That is directly relevant to Fusion Middleware and Hyperion estates carrying this month’s six maximum-severity findings, to WebLogic deployments still exposed to the KEV-listed proxy plug-in flaw, and to PeopleSoft and E-Business Suite environments where the practical threat continues to come from vulnerabilities patched months ago rather than from anything new in September.

Waratek customers should contact our Customer Success team for guidance on which existing RASP rules already cover the vulnerability classes represented in the September 2026 CSPU.

Frequently asked questions

Is anything in this release under active exploitation right now?

Nothing first disclosed in the September CSPU has been publicly confirmed as exploited as of publication. CVE-2026-35273 and CVE-2026-35278 in PeopleSoft PeopleTools, CVE-2026-46817 in E-Business Suite Oracle Payments, and CVE-2026-21962 in the WebLogic Server Proxy Plug-in are all confirmed exploited, all affect products covered by this release, and all should be verified as remediated before turning to this month’s new patches.

Should we prioritize the six 10.0 issues first?

Prioritize by exposure and exploitation status first, and by score second. Verify remediation of the four confirmed exploited vulnerabilities above, then take the six maximum-severity findings on anything externally reachable: five in Fusion Middleware, spanning Access Manager, Oracle Forms, Internet Directory, Platform Security for Java and WebLogic Server, plus the one in Hyperion Financial Management. All six require no authentication. From there, move to the Oracle Payments component in E-Business Suite and the PeopleSoft integration layer.

Is PeopleSoft urgent this month?

Not on severity grounds. Its ceiling is 8.8 this month, the first time in recent CSPUs that PeopleSoft has had no entry at or above 9.0. The caveat is that PeopleSoft remains under sustained, named adversary attention independent of this release, so confirming coverage of the May and June zero days matters more than this month’s patch count.

Is Java SE urgent this month?

No. Its highest score is 8.1, all three patches sit in the GraalVM Compiler component, and none reach the critical band. Apply on a normal cycle unless you run GraalVM and expose compiler-relevant functionality to untrusted remote input. The structural caveat is unchanged from prior months: the JVM is the execution layer for the products that do carry this release’s critical issues.

We cannot regression test 673 patches within the monthly window. What are our options?

Prioritize internet-facing and unauthenticated attack surface first, since 247 of the 673 patches address issues exploitable with no credentials. Establish compensating controls, such as a runtime rule, for what cannot be patched immediately so the exposure window is covered while testing proceeds. Runtime protection is designed for exactly this gap, reducing risk on day one without a code change or an outage.

For more information

Waratek customers should contact customersuccess@waratek.com for guidance on which RASP rules already cover CVEs in the September 2026 CSPU.

Prospects evaluating Waratek can contact sales@waratek.com for a protection assessment.

Source advisory: https://www.oracle.com/security-alerts/cspusep2026.html

This bulletin is a security news summary compiled by Waratek for customers and prospects from Oracle’s published Critical Security Patch Update Advisory for September 2026 and its risk matrices, and from public reporting on active exploitation. It is not an official Oracle publication. All Oracle product names are trademarks of Oracle.

About Waratek

Waratek offers Waratek IAST+RASP, the only compiler-based, runtime application tools that find vulnerabilities in the pre-production development pipeline, block attacks in production, and virtually patch flaws with no downtime or source code changes. Waratek IAST watches code execute to identify security flaws with absolute certainty, eliminating the “guesswork” and alert fatigue associated with traditional scanners. Waratek RASP intercepts and terminates unsafe operations at the JVM level, stopping attempts to change app behavior in attacks aimed at known and Zero Day vulnerabilities. Waratek is a trusted partner for organizations in global financial services, hospitality, healthcare, technology and other industries. Waratek has offices in Dublin, Ireland and Chicago, Illinois.

Share Article