Oracle released its quarterly patch day, known as the Critical Security Patch Update or CSPU, in the middle of the month. In total, the company's developers provide 673 software patches for numerous products across Oracle's portfolio.
IT teams should carefully review the patch day overview and check whether their own environment uses any of the affected products. Some of the flaws require prompt attention, since Oracle rates them as critical risk. Attackers could cause significant damage through them, which can be prevented by applying the updates promptly.
Critical flaws across numerous products
Vulnerabilities rated critical by CVSS score affect, among others, the Oracle Application Testing Suite, Oracle Communications Unified Assurance, Oracle Applications Framework, Oracle Document Management and Collaboration, Oracle Mobile Application Server, the Oracle Enterprise Manager Base Platform, and Oracle Enterprise Manager for Fusion Middleware. Oracle Access Manager, Oracle Forms, Oracle Internet Directory, Oracle Platform Security for Java, Oracle WebLogic Server, Oracle WebCenter Portal, and Oracle WebCenter Sites are affected too, along with the Service Delivery Platform, Oracle Data Integrator, Oracle Identity Manager and its connector, Oracle WebCenter Enterprise Capture, and Oracle Managed File Transfer. Further critical flaws sit in Oracle Business Intelligence Enterprise Edition, Oracle BI Publisher, Oracle Hyperion Financial Management, Oracle Hyperion Data Relationship Management, several Siebel products, as well as Oracle Product Lifecycle Analytics and Oracle Agile PLM.
Plenty of high-risk flaws too
Besides the critical vulnerabilities, Oracle rates numerous additional flaws as high risk. Administrators shouldn't put off these updates either, in order to keep their IT environment's attack surface as small as possible. August's CSPU release was considerably larger, closing nearly 1,000 vulnerabilities, and the next regular Oracle Critical Patch Update (CPU) is scheduled for October 2026 as usual.