Skip to content

Security2 publishers2 min readPublished

Half of Oracle's Fusion Middleware patches fix flaws reachable without a login

Oracle's fifth monthly Critical Security Patch Update since May concentrates its unauthenticated remote flaws in Fusion Middleware and Hyperion, while the largest single batch of patches went to E-Business Suite.

The Watch · Security desk

Illustration accompanying Half of Oracle's Fusion Middleware patches fix flaws reachable without a login

What happened

  • Oracle shipped its September 2026 Critical Security Patch Update on September 15, with 673 patches covering 672 unique CVEs across 17 product families.
  • More than 240 of the newly patched flaws can be exploited over a network without authentication, and more than 100 are rated critical severity.
  • E-Business Suite took the largest batch at 159 patches, followed by Fusion Middleware at 153 and Hyperion at 102, with Siebel CRM and Analytics next.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure An attacker with network reach to a Fusion Middleware or Hyperion host is inside the threat model for about half of each family's fixes, before any credential theft is needed.
  • constraint Because 61.5 percent of the patches land in three families, the work cannot be spread evenly across teams: the same middleware and applications groups absorb most of the release.
  • decision Triage by batch size puts E-Business Suite first, where 12 percent of fixes are unauthenticated; triage by reachability puts Fusion Middleware first, where 51 percent are.
  • precedent On a monthly cadence, any family that needs more than 30 days of testing and restart windows will be holding two open batches at once.

Reachability separates the families. Fusion Middleware's patches include 78 flaws exploitable over a network with no credentials, about half of that family's total [10][19]. Hyperion has 50, close to half again [11][19]. E-Business Suite, which took the largest batch, has 19, or 12 percent [8][19].

Those three families hold 414 of the 673 patches [18] and 147 of the unauthenticated remote flaws, roughly three-fifths of that total [17][4]. I would sequence by the second number. The 128 no-credential flaws in Fusion Middleware and Hyperion [20] are the ones an attacker can try from a network position, with no phishing step first.

The 800-plus total comes from bundling. Oracle counts 672 unique CVEs in the advisory's risk matrices and notes more than 130 further CVEs fixed by patches issued for other flaws, so at least 802 CVEs are in scope [3][21]. Communications received 31 patches, and half of them resolve more than 125 additional CVEs [13]. Nearly all of the extra CVE count sits in that one family [23]. Siebel CRM took 63 patches and Analytics 50 [12].

Oracle moved the CSPU to a monthly cycle in May 2026, sitting between the larger quarterly Critical Patch Updates and covering a focused set of high-severity issues [16]. September is the fifth of those monthly releases [22].

Oracle makes no mention of any of these vulnerabilities being exploited in the wild, and warns customers that threat actors regularly exploit flaws in its products [14]. "In some instances, it has been reported that attackers have been successful because targeted customers had failed to apply available Oracle patches. Oracle therefore strongly recommends that customers remain on actively-supported versions and apply security patches without delay," Oracle said [15].

Tenable's breakdown puts critical patches at 104, or 15.5 percent of the release, with high-severity patches at 74.7 percent [6][7]. The two bands together account for 90.2 percent of the 673 updates [24].

What to watch

  • Any of the 672 CVEs landing in CISA's Known Exploited Vulnerabilities catalog.
  • Public proof-of-concept code for one of the 78 unauthenticated Fusion Middleware flaws.
  • Whether October's CSPU adds another triple-digit batch to E-Business Suite or Fusion Middleware.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories