<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/oracle-s-september-patches-put-fusion-middleware-back-in-the-hot-seat-xhsmpxeic" -->

---
title: Oracle’s September patches put Fusion Middleware back in...
description: Oracle&#x27;s September 2026 Critical Security Patch Update delivers 673 patches across 17 product families, with E-Business Suite (159) and Fusion Middleware (153)...
canonical: https://daily.dev/posts/oracle-s-september-patches-put-fusion-middleware-back-in-the-hot-seat-xhsmpxeic
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Oracle’s September patches put Fusion Middleware back in the hot seat | daily.dev
og:description: Oracle&#x27;s September 2026 Critical Security Patch Update delivers 673 patches across 17 product families, with E-Business Suite (159) and Fusion Middleware (153)...
og:url: https://daily.dev/posts/oracle-s-september-patches-put-fusion-middleware-back-in-the-hot-seat-xhsmpxeic
og:image: https://api.daily.dev/og/posts/XHsMPXeIc.png
og:image:alt: Oracle’s September patches put Fusion Middleware back in the hot seat
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Oracle’s September patches put Fusion Middleware back in the hot seat

**[CSO Online](https://daily.dev/sources/csoonline)** · 4 min read · 0 upvotes · 0 comments

## Summary

Oracle's September 2026 Critical Security Patch Update delivers 673 patches across 17 product families, with E-Business Suite (159) and Fusion Middleware (153) receiving the most fixes. Fusion Middleware contains five CVSS 10.0 flaws affecting Access Manager, Forms, Internet Directory, Platform Security for Java, and WebLogic Server, plus 13 CVSS 9.9 vulnerabilities. A sixth 10.0 flaw hit Hyperion Financial Management. All the maximum-severity bugs are remotely exploitable without authentication, though none are confirmed exploited in the wild. Oracle recently moved from quarterly to monthly patch cycles and urges customers on supported versions to apply fixes immediately, warning that mitigations like blocking network protocols are temporary and can break functionality.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.csoonline.com/article/4222875/oracles-september-patches-put-fusion-middleware-back-in-the-hot-seat-2.html>

## Questions this post answers

### How many critical vulnerabilities did Oracle's September 2026 patch update fix in Fusion Middleware?

Oracle's September 2026 Critical Patch Update fixed 153 Fusion Middleware vulnerabilities, including five rated CVSS 10.0 and 13 rated CVSS 9.9. The maximum-severity flaws hit Oracle Access Manager, Oracle Forms, Oracle Internet Directory, Oracle Platform Security for Java, and Oracle WebLogic Server, all remotely exploitable without authentication and requiring no user interaction.

_Teams tracking Oracle middleware exposure can follow patch cycle details like this on daily.dev._

### Are the Oracle Fusion Middleware CVSS 10.0 vulnerabilities from September 2026 being actively exploited?

No, Oracle did not mark any of the six CVSS 10.0 vulnerabilities or the 13 CVSS 9.9 vulnerabilities from the September 2026 update as exploited in the wild. Still, Oracle urged immediate patching, noting it continues to receive reports of successful attacks against customers who had not applied earlier available fixes.

_daily.dev helps security teams stay ahead of Oracle CVE disclosures before exploitation begins._

### Why did Oracle switch from quarterly to monthly critical patch updates?

Oracle accelerated its Critical Patch Update rhythm from quarterly to monthly to counter increasing AI-driven cybersecurity threats. The change means customers face more frequent patch cycles, and Oracle has warned that skipping any monthly release should not be assumed covered by later updates, urging review of prior CSPUs and quarterly CPUs for missed fixes.

_Following Oracle's patch cadence shifts on daily.dev helps teams keep upgrade schedules on track._

## Similar posts on daily.dev

- [Oracle releases 245 new security patches, all rated ‘high-priority security’](https://daily.dev/posts/oracle-releases-245-new-security-patches-all-rated-high-priority-security--aiut2jpue) · CSO Online · 1 upvotes · 0 comments
- [Oracle Critical Security Patch Update June 2026](https://daily.dev/posts/oracle-critical-security-patch-update-june-2026-oanshrtv4) · Tenable Blog · 0 upvotes · 0 comments
- [Oracle July 2026 Critical Patch Update 1235 CVEs](https://daily.dev/posts/oracle-july-2026-critical-patch-update-1235-cves-irkciptx1) · Tenable Blog · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#oracle](https://daily.dev/tags/oracle)

[View this post on daily.dev](https://daily.dev/posts/oracle-s-september-patches-put-fusion-middleware-back-in-the-hot-seat-xhsmpxeic)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Oracle’s September patches put Fusion Middleware back in the hot seat","url":"https://daily.dev/posts/oracle-s-september-patches-put-fusion-middleware-back-in-the-hot-seat-xhsmpxeic","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/oracle-s-september-patches-put-fusion-middleware-back-in-the-hot-seat-xhsmpxeic"},"datePublished":"2026-09-16T15:58:08.648Z","dateModified":"2026-09-16T16:25:35.185Z","description":"Oracle's September 2026 Critical Security Patch Update delivers 673 patches across 17 product families, with E-Business Suite (159) and Fusion Middleware (153)...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/bf58ce8e41686e8c3e6a701759c1bb71?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/bf58ce8e41686e8c3e6a701759c1bb71?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"CSO Online","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"CSO Online","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/98667e4b5cac46cf9c470819c6cf71cd","url":"https://daily.dev/sources/csoonline"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/oracle-s-september-patches-put-fusion-middleware-back-in-the-hot-seat-xhsmpxeic","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,oracle","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"CSO Online","item":"https://daily.dev/sources/csoonline"},{"@type":"ListItem","position":3,"name":"Oracle’s September patches put Fusion Middleware back in the hot seat"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/oracle-s-september-patches-put-fusion-middleware-back-in-the-hot-seat-xhsmpxeic#faq","mainEntity":[{"@type":"Question","name":"How many critical vulnerabilities did Oracle's September 2026 patch update fix in Fusion Middleware?","acceptedAnswer":{"@type":"Answer","text":"Oracle's September 2026 Critical Patch Update fixed 153 Fusion Middleware vulnerabilities, including five rated CVSS 10.0 and 13 rated CVSS 9.9. The maximum-severity flaws hit Oracle Access Manager, Oracle Forms, Oracle Internet Directory, Oracle Platform Security for Java, and Oracle WebLogic Server, all remotely exploitable without authentication and requiring no user interaction. Teams tracking Oracle middleware exposure can follow patch cycle details like this on daily.dev."}},{"@type":"Question","name":"Are the Oracle Fusion Middleware CVSS 10.0 vulnerabilities from September 2026 being actively exploited?","acceptedAnswer":{"@type":"Answer","text":"No, Oracle did not mark any of the six CVSS 10.0 vulnerabilities or the 13 CVSS 9.9 vulnerabilities from the September 2026 update as exploited in the wild. Still, Oracle urged immediate patching, noting it continues to receive reports of successful attacks against customers who had not applied earlier available fixes. daily.dev helps security teams stay ahead of Oracle CVE disclosures before exploitation begins."}},{"@type":"Question","name":"Why did Oracle switch from quarterly to monthly critical patch updates?","acceptedAnswer":{"@type":"Answer","text":"Oracle accelerated its Critical Patch Update rhythm from quarterly to monthly to counter increasing AI-driven cybersecurity threats. The change means customers face more frequent patch cycles, and Oracle has warned that skipping any monthly release should not be assumed covered by later updates, urging review of prior CSPUs and quarterly CPUs for missed fixes. Following Oracle's patch cadence shifts on daily.dev helps teams keep upgrade schedules on track."}}]}
```

