Oracle released 673 security patches on 15 September, and six of them carry a CVSS score of 10.0, the highest the scale goes. Last month's equivalent release was bigger, at 943 patches, and contained exactly one perfect 10. The batch got smaller and the top of it got worse.
All six of the maximum score flaws share a profile in Oracle's risk matrix: reachable over the network, low attack complexity, no privileges required, no user interaction, and scored as reaching beyond the component they sit in. Oracle marks each as remotely exploitable without authentication, which in the advisory's own words means it "may be exploited over a network without requiring user credentials".
Six tens, and one component keeps coming back
They are CVE-2026-71133 in the authentication engine of Oracle Access Manager, CVE-2026-83021 in the WebLogic Server web container, CVE-2026-83020 in Oracle Platform Security for Java, CVE-2026-83099 in Oracle Forms, CVE-2026-87230 in the security component of Hyperion Financial Management, and CVE-2026-83059 in the LDAP server of Oracle Internet Directory.
The last one deserves a second look. Oracle Internet Directory's LDAP server is precisely where August's lone 10.0 sat, and in this release it collects four more entries scored 9.9. A directory server is what everything else on the network asks who a user is and what they are allowed to do, so a component that keeps producing maximum severity findings is an uncomfortable place to see a pattern form.
Where the 673 actually land
Two product families take almost half the release between them. Oracle E-Business Suite draws 159 patches, 19 of which Oracle says may be remotely exploitable without authentication, and Oracle Fusion Middleware draws 153, with 78 carrying that flag. Hyperion follows on 102 patches and 50 remotely exploitable without authentication, then Siebel CRM on 63, Oracle Analytics on 50, Communications on 31 and Commerce on 27. Across the whole advisory, 247 of the 673 entries are marked remotely exploitable without authentication.
The affected version lists are long and specific. Database Server covers 19.3 to 19.32, 21.3 to 21.23 and 23.4.0 to 23.26.3. E-Business Suite covers 12.2.3 to 12.2.15 and V16. WebLogic Server covers 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Java SE, VirtualBox, PeopleSoft, MySQL and the Banking product line all appear too.
Not the quarterly cycle you planned maintenance around
This is a Critical Security Patch Update, which Oracle describes as targeted, high priority security fixes in a smaller, more focused format that is easier to apply with minimal disruption. It complements the cumulative quarterly Critical Patch Updates rather than replacing them, which is the detail that catches teams whose change windows are built around the quarterly rhythm. Hong Kong's HKCERT relayed the release to its constituents in a short bulletin on 16 September, but the substance is in Oracle's own advisory and the risk matrices attached to it, and that is the document to work from.
Oracle says the victims it hears about had the patch
The advisory carries a warning Oracle has repeated for years and plainly means. It says it continues to receive reports of attempts to exploit vulnerabilities it has already patched, and that attackers have sometimes succeeded because the targeted customer had not applied the fix that was available. The company's recommendation is to stay on actively supported versions and patch without delay. That is not an abstract risk here: a maximum severity flaw in Oracle HTTP Server reached CISA's Known Exploited Vulnerabilities catalog last month. The 673 entries in this release are a queue, and the six tens are the front of it.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.