Vulnerabilities & Exploits

Oracle’s September Bulletin Spans the Enterprise Stack

Oracle’s September 2026 security bulletin discloses 672 vulnerabilities, including 104 critical flaws and a CVSS 10.0 bug, CVE-2026-87230, in Oracle Hyperion Financial Management. The same bulletin reaches across Helidon, Access Manager, Coherence, BI Publisher, Oracle Business Intelligence Enterprise Edition, and multiple banking and Agile product lines.

The practical issue is not one product in isolation but how much of a shared Oracle estate sits on the same patch calendar. In plain terms, identity, reporting, banking, and engineering components can depend on one another, so fixing one application may ripple into the services that feed or consume it.

For Oracle-heavy shops, the exposure is the coordinated update problem: the bulletin is broad enough that the hard part is sequencing change without breaking adjacent workflows. What remains after patching depends on which linked services were left behind, not just which CVEs were closed.

1 source · Sep 18

CVEs in this update

6 CVEs

Across Fusion Middleware, Oracle Internet Directory, Oracle Platform Security for Java, and related packages.

6 critical · 0 high · 0 medium · 0 low

0 in CISA KEV · 0 with EPSS above 1%

Highest severity: CVE-2026-83059 · 10.0 CRITICAL

Highest EPSS: CVE-2026-83059 · 0.48%

Timeline

Sources

Part of the PlainSec briefing for 2026-09-19

Every edition of this story: Oracle’s September Bulletin Spans the Enterprise Stack

More from today