Oracle Releases 673 Security Patches in September Update, Resolving 800+ Vulnerabilities

Oracle released 673 new security patches this week as part of its quarterly Critical Security Patch Update, addressing more than 800 vulnerabilities across its product portfolio.

The update resolves 672 unique CVEs documented across 17 risk matrices, plus an additional 130+ CVEs addressed through patches for other flaws. More than 100 of the newly patched security defects carry a critical severity rating, and over 240 can be exploited remotely without requiring authentication.

Products with Most Patches

Oracle E-Business Suite received the largest share of patches: 159 total, including 19 that address remotely exploitable vulnerabilities. Fusion Middleware followed closely with 153 patches, 78 of which fix flaws that can be triggered over the network without credentials. Hyperion rounded out the top three with 102 patches, 50 of which cover remotely exploitable issues.

Additional products receiving significant updates include Siebel CRM (63 patches), Analytics (50), Communications (31), Commerce (27), Supply Chain Products (19), Virtualization (19), and PeopleSoft (16). The Communications update is notable because roughly half of its patches address more than 125 additional CVEs beyond those listed in the risk matrices.

Other Oracle products updated this month include Database Server, Enterprise Manager, Financial Services Applications, Application Testing Suite, Java SE, Autonomous Health Framework, and Utilities Applications.

Oracle Recommends Immediate Action

Oracle has not reported any of these vulnerabilities being actively exploited in the wild. However, the company is urging customers to apply updates promptly, noting that threat actors regularly target Oracle products.

“In some instances, it has been reported that attackers have been successful because targeted customers had failed to apply available Oracle patches,” the company stated. “Oracle therefore strongly recommends that customers remain on actively-supported versions and apply security patches without…”

Leave a Comment