XT.PT Patch cadence → This story
Analysis Patch cadence

Oracle's "smaller" patch release has 673 fixes in it

The fourth Oracle CSPU brings 10.0-rated fixes for WebLogic, Access Manager and Internet Directory, and a monthly patch calendar that no longer rolls up until the quarterly CPU.

server rack

Oracle's September Critical Security Patch Update went out on September 15, 2026. It is the fourth release under a program Oracle started this spring, and the advisory describes the program in one sentence:

A Critical Security Patch Update (CSPU) provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption.

Oracle, Critical Security Patch Update Advisory, September 2026

The same advisory then says: "This Critical Security Patch Update contains 673 new security patches across the product families listed below." That is the tension worth a closer look, because it changes how anyone running Oracle on-premises has to plan patching.

Four releases, and the "smaller" one keeps growing

Oracle's security-alerts index says "The first Critical Security Patch Update was released on May 28, 2026." Since then, each advisory has opened with its own total:

| Release | Type | New security patches | |---|---|---| | May 2026 | CSPU | 35 | | June 2026 | CSPU | 245 | | July 2026 | CPU (quarterly) | 1448 | | August 2026 | CSPU | 943 | | September 2026 | CSPU | 673 |

So the "smaller" format is smaller than the quarterly Critical Patch Update, but not small. August's CSPU carried roughly two thirds of July's quarterly count, one month later. September's is the second-largest CSPU so far.

The totals come straight from each advisory's opening paragraph. What they don't say is whether the quarterly releases are shrinking as a result. The next quarterly CPU, on October 20, is the first test of that.

What is in September's batch

The per-family breakdown in the advisory's risk matrices puts most of the volume in a few places: 159 patches for Oracle E-Business Suite, 153 for Fusion Middleware (78 of them "remotely exploitable without authentication"), 102 for Hyperion (50 unauthenticated), 63 for Siebel CRM and 50 for Oracle Analytics. Oracle Database products get 13.

By XT.PT's count of the risk matrices, six entries carry a CVSS 3.1 base score of 10.0, 15 score 9.9, 44 score 9.8, and 104 score 9.0 or higher. The six 10.0 entries, all rated network-reachable, low complexity, no privileges, no user interaction and scope changed:

  • CVE-2026-71133, Oracle Access Manager, Authentication Engine (12.2.1.4.0, 14.1.2.1.0)
  • CVE-2026-83099, Oracle Forms, Forms Services (12.2.1.19.0, 14.1.2.0.0)
  • CVE-2026-83059, Oracle Internet Directory, OID LDAP Server (12.2.1.4.0, 14.1.2.1.0)
  • CVE-2026-83020, Oracle Platform Security for Java, Centralized Thirdparty Jars (12.2.1.4.0, 14.1.2.0.0)
  • CVE-2026-83021, Oracle WebLogic Server, Web Container (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0)
  • CVE-2026-87230, Oracle Hyperion Financial Management, Security (11.2.26.0.0)

On the database side, the affected Database Server versions are listed as 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Of the 11 Database patches, 5 are remotely exploitable without authentication and 2 apply to client-only installations.

The advisory does not say any of these specific flaws are being exploited. It carries only Oracle's standing warning that it "continues to periodically receive reports of attempts to maliciously exploit vulnerabilities for which Oracle has already released security patches."

The part that changes your runbook: not cumulative

For years the operating rule for Oracle was simple for products that receive cumulative fixes: apply the latest quarterly CPU and you are current. The CPU FAQ still says so, and then adds the exception:

"As much as possible, Oracle tries to make Critical Patch Updates cumulative; that is, each Critical Patch Update contains the security fixes from all previous Critical Patch Updates, Critical Security Patch Updates and Security Alerts. Critical Security Patch Updates are not cumulative."

Read together, that means a CSPU is something you apply on its own schedule, and the next quarterly CPU is where those fixes get rolled up. For products whose fixes ship as one-off patches, the FAQ is explicit that the bookkeeping is on the customer: "It is necessary for these products to refer to previous Critical Patch Update, Critical Security Patch Update, or Security Alert advisories to find all the patches that may need to be applied."

A shop that skipped August's 943 patches and waits for October cannot assume September's advisory covers them. The September advisory says as much under "Skipped Security Patch Updates," pointing customers back to earlier CPU and CSPU advisories.

A monthly calendar, with a quarterly spine

The cadence is now fixed. The alerts index says CSPUs "will be released on the third Tuesday of February, March, May, June, August, September, November, and December," which fills the months between the quarterly CPUs. The September advisory lists the next four dates: October 20, 2026 (CPU), November 17 (CSPU), December 15 (CSPU) and January 19, 2027 (CPU). Oracle also publishes a pre-release announcement "on the Thursday preceding each Critical Security Patch Update release beginning in June 2026."

Two limits apply. CSPUs "are available to customers with valid support contracts," and the advisory says fixes are provided "only for product versions that are covered under the Premier Support or Extended Support phases of the Lifetime Support Policy." Older releases are "not tested for the presence of vulnerabilities," though Oracle adds it is "likely that earlier versions of affected releases are also affected."

What to do with it

The practical reading for an operator:

  1. Treat the CSPU as a monthly patch window, not a preview of the quarterly one. The 10.0 entries in Access Manager, Internet Directory and WebLogic sit in identity and application-server components; waiting five weeks for the October CPU is a choice to carry them.
  2. Track CSPUs individually. Because they are not cumulative, an asset inventory that records only "last CPU applied" no longer describes an Oracle estate's patch state.
  3. Use the stated interim measures only as interim. Oracle's workaround section suggests "blocking network protocols required by an attack" or removing unneeded privileges, and warns that "Neither approach should be considered a long-term solution as neither corrects the underlying problem."

Oracle frames the program as easier to apply. The first four releases show more frequent patching, not lighter patching, and a patch history that now has to be tracked month by month.

Primary sources: Oracle Critical Security Patch Update Advisory, September 2026, Oracle Critical Security Patch Update Advisory, August 2026, June 2026, May 2026, Oracle Critical Patch Update Advisory, July 2026, Oracle Security Alerts index, Oracle CPU/CSPU FAQ, read 2026-09-22.

Corrections and source documents: contact the desk
Read next →
Read next
Edge devices · 4 min

NetScaler 14.1-73.37 fixes eight CVEs, and the exploited CVE-2026-88771 needs no special configuration

WordPress · 4 min

WordPress 7.1.2 fixes CVE-2026-87902, a page-template bug exploited within three days