Oracle September 2026 CSPU: 673 new patches; Access Manager and OID LDAP at CVSS 10.0
Oracle Critical Security Patch Update advisory — September 2026 (Rev 1, 15 September 2026) contains 673 new security patches across product families. SecurityWeek (16 September 2026) notes the matrices cover on the order of 800+ CVE IDs including third-party component fixes, with more than 100 critical-severity issues and over 240 remotely exploitable without authentication. Largest batches include Oracle E-Business Suite, Fusion Middleware, and Hyperion. Notable CVSS 10.0 entries include Oracle Access Manager Authentication Engine CVE-2026-71133 (HTTP, unauthenticated network, versions 12.2.1.4.0 and 14.1.2.1.0) and Oracle Internet Directory OID LDAP Server CVE-2026-83059 (LDAP, unauthenticated network, 12.2.1.4.0 and 14.1.2.1.0). Oracle again warns of exploitation attempts against already-patched issues where customers delayed applying updates; no claim in the advisory that these September flaws are exploited in the wild. Apply the September 2026 CSPU for each product family you run. Distinct from desk card oracle-cspu-20260818. Primary: Oracle CSPU September 2026; wire: SecurityWeek 16 Sep.
- Product
- Oracle product families in the September 2026 CSPU (incl. E-Business Suite, Fusion Middleware, Hyperion, Access Manager, OID, Database Server, Java SE, others)
- Versions
- See September 2026 CSPU risk matrices; e.g. Access Manager 12.2.1.4.0 / 14.1.2.1.0; OID 12.2.1.4.0 / 14.1.2.1.0 among others
- CVSS
- Up to (CVE-2026-71133 Access Manager; CVE-2026-83059 OID LDAP, Oracle)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- September 2026 Critical Security Patch Update for each affected product family; prioritise unauthenticated network 9.8–10.0 matrix rows
Primary: Oracle CSPU September 2026 (Rev 1, 15 Sep 2026) · Vendor: Oracle (vendor) · CVE: CVE-2026-71133, CVE-2026-83059 · SecurityWeek — Oracle September 2026 CSPU (16 Sep 2026)
