CTIPilot
← Back to the live brief
HIGHCVE-2026-83021 +5NATOA2vulnerability

Oracle's September 2026 Critical Security Patch Update carries six unauthenticated CVSS 10.0 flaws across WebLogic Server, Access Manager, Forms, Internet Directory, Platform Security for Java and Hyperion Financial Management

Six CVSS 10.0 flaws needing no credential and no user interaction, in the middleware tier that fronts everything else

Defender actions

  • Check every Oracle Fusion Middleware and Hyperion deployment against the affected component version strings (WebLogic Server 12.2.1.4.0 / 14.1.1.0.0 / 14.1.2.0.0; Access Manager and Internet Directory 12.2.1.4.0 / 14.1.2.1.0; Forms 12.2.1.19.0 / 14.1.2.0.0; Platform Security for Java 12.2.1.4.0 / 14.1.2.0.0; Hyperion Financial Management 11.2.26.0.000) and apply the September 2026 Critical Security Patch Update, which is an off-quarter release a January/April/July/October patch calendar does not schedule.
  • Confirm that no Oracle Internet Directory LDAP listener, WebLogic web container or Access Manager authentication endpoint answers from outside its administrative network segment; all six flaws need no credential and no user interaction, so reachability is the whole of the exposure.

Analysis

Oracle published its September 2026 Critical Security Patch Update on 2026-09-15 (Rev 1, initial release) with 673 new security patches across its product families; Oracle Fusion Middleware alone accounts for 153 of them, and Oracle states that "78 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials" (Oracle, 2026-09-15). Six flaws in the release carry a CVSS 3.1 base score of 10.0 in Oracle's own risk matrix with Attack Vector Network, Attack Complexity Low, Privileges Required None, User Interaction None and Scope Changed, meaning an unauthenticated request across the network reaches high confidentiality and integrity impact and crosses a security boundary (the first five also reach high availability impact; Hyperion Financial Management's is rated none): CVE-2026-83021 in the Web Container of Oracle WebLogic Server over HTTP, CVE-2026-71133 in the Authentication Engine of Oracle Access Manager over HTTP, CVE-2026-83099 in Oracle Forms Services over HTTP, CVE-2026-83059 in the OID LDAP Server of Oracle Internet Directory over LDAP, CVE-2026-83020 in the centralized third-party jars of Oracle Platform Security for Java over HTTP, and CVE-2026-87230 in the Security component of Oracle Hyperion Financial Management over HTTP (Oracle, 2026-09-15). The Netherlands' national cyber-security centre relayed the Fusion Middleware half of the release as advisory NCSC-2026-0372 on 2026-09-16 and assigned it priority "Hoog", its high rating (NCSC-NL, 2026-09-16).

The Critical Security Patch Update is Oracle's second, higher-frequency release line, published alongside the quarterly cumulative Critical Patch Update rather than replacing it: Oracle describes it as providing "targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption" and says these updates "complement Oracle’s existing quarterly cumulative Critical Patch Updates (CPUs)" (Oracle, 2026-09-15). A patch calendar built only around the January, April, July and October quarterly dates therefore leaves the September release, and the four other off-quarter releases in the year, unscheduled.

Oracle discloses no exploitation technique, no proof-of-concept status and no in-the-wild activity for any of the six, which is its standing advisory practice; no source in this release names an exploited flaw. What forces the timeline is the shape of the flaws rather than an exploitation report. Each of the six is reachable by an unauthenticated network request against a component that exists to sit in front of other systems or to hold what they rely on: WebLogic's web container, Access Manager's authentication engine, an Internet Directory LDAP listener, Forms Services, the shared Java security jars underneath Fusion Middleware, and Hyperion Financial Management's own security component. Five of them are the single-sign-on, directory and application-server tiers that Swiss federal, cantonal and communal estates run legacy identity services on, and a Scope Changed rating on an authentication engine means the compromise does not stay inside the component that carries the flaw. The sixth sits elsewhere: Hyperion Financial Management is a financial-consolidation application from Oracle's separate Hyperion family, so it is the finance estate rather than the identity estate that needs checking for it.

Triage: exploitation of these components produces authentication and application-tier telemetry, not endpoint telemetry. On the identity tier, look for successful authorization decisions from Access Manager with no preceding credential-validation event, and for LDAP binds or searches against the OID listener from source ranges that no application integration uses. On the application tier, look for requests to WebLogic or Forms endpoints that return successfully without a prior session-establishment request in the same log sequence. Ordinary integrations and health checks produce the same request types, so the discriminator is the missing predecessor event, not the request itself.

Cited evidence

This Critical Security Patch Update contains 153 new security patches for Oracle Fusion Middleware.

78 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.

A Critical Security Patch Update (CSPU) provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption.

Oracle 2026-09-15

Sources2

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.