Cyber Resilience
← All news

Patch bundle: Oracle Oracle Critical Security Patch Update Advisory - September 2026 — 808 CVEs, 104 critical

Sources (2)
What this means for you — Security leader:Patch the four Critical CVEs called out by Oracle (CVE-2026-71133, CVE-2026-83020, CVE-2026-83021, CVE-2026-83059) out-of-band this week; the remaining 800+ CVEs ride your normal cycle.
What this means for you — Lean IT orgs:Check whether you run any Oracle software that receives these updates. If you do, apply the four Critical fixes named above as soon as possible this week; everything else can wait for your usual maintenance window.
What this means for you — MSP:Review client estates for Oracle products in scope. Prioritize the four named Critical CVEs this week; the rest of the bundle follows each client's normal patch cadence.
What this means for you — Researcher:Oracle's September 2026 Critical Patch Update fixes 808 CVEs, 104 of them Critical. The four explicitly highlighted CVEs (CVE-2026-71133, CVE-2026-83020, CVE-2026-83021, CVE-2026-83059) are the ones to watch for immediate exploitation risk.