Vulnerabilities · 3 days ago
Oracle’s September 2026 security bulletin discloses 672 vulnerabilities, including 104 critical flaws and a CVSS 10.0 bug, CVE-2026-87230, in Oracle Hyperion Financial Management. The same bulletin reaches across Helidon, Access Manager, Coherence, BI Publisher, Oracle Business Intelligence Enterprise Edition, and multiple banking and Agile product lines.
The practical issue is not one product in isolation but how much of a shared Oracle estate sits on the same patch calendar. In plain terms, identity, reporting, banking, and engineering components can depend on one another, so fixing one application may ripple into the services that feed or consume it.
For Oracle-heavy shops, the exposure is the coordinated update problem: the bulletin is broad enough that the hard part is sequencing change without breaking adjacent workflows. What remains after patching depends on which linked services were left behind, not just which CVEs were closed.
CVEs in this update
6 CVEs
Across Fusion Middleware, Oracle Internet Directory, Oracle Platform Security for Java, and related packages.
6 critical · 0 high · 0 medium · 0 low
0 in CISA KEV · 0 with EPSS above 1%
Highest severity: CVE-2026-83059 · 10.0 CRITICAL
Highest EPSS: CVE-2026-83059 · 0.48%
1 source covering this story
Boletín de seguridad de Oracle: septiembre de 2026
Oracle ha publicado 672 vulnerabilidades: 104 de severidad crítica, 503 de severidad alta, 58 de sever
Part of the PlainSec briefing for 2026-09-21