Oracle’s September patches put Fusion Middleware back in the hot seat
Executive Take
Any company running Oracle Fusion Middleware or E-Business Suite now has a narrow window before attackers reverse-engineer these patches into working exploits. Delaying this update is a board-level risk, not an IT backlog item.
Executive Summary
Oracle's September 2026 patch update fixes 673 vulnerabilities across 17 product families. E-Business Suite leads with 159 fixes, Fusion Middleware follows with 153, including six flaws rated maximum severity (CVSS 10.0) that can be exploited remotely without login credentials. Oracle urges immediate patching, citing ongoing successful attacks on unpatched systems.
Why It Matters
Technology and cybersecurity leaders running Oracle systems face six maximum-severity flaws exploitable without a password. GCC leaders should check which back-office hubs still run unsupported Oracle versions, since those get no fix at all.
Bizquad Perspective
The real risk isn't this patch, it's the backlog: Oracle's monthly cadence assumes customers were current, and most enterprise estates running unsupported versions get zero protection.