T
Threats
Oracle Fusion Middleware Critical Vulnerabilities
Overview
CVE: CVE-2026-70748, CVE-2026-70756, CVE-2026-70757, CVE-2026-70913, CVE-2026-71133, CVE-2026-71163, CVE-2026-73940, CVE-2026-73944, CVE-2026-73945, CVE-2026-73946, CVE-2026-73947, CVE-2026-73948, CVE-2026-73950, CVE-2026-73952, CVE-2026-73953, CVE-2026-73956, CVE-2026-73957, CVE-2026-73961, CVE-2026-73962, CVE-2026-73963
Severity: Critical
Date: 16 September 2026
Oracle has released its September 2026 Critical Security Patch Update, including fixes for 20 critical vulnerabilities in Oracle Fusion Middleware products. The affected Oracle components are exposed through HTTP, HTTPS, T3 or IIOP depending on the CVE. Many can be exploited remotely without authentication and can result in product takeover or unauthorised access to critical data.
Affected Versions
Oracle WebLogic Server
Affected: 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0
Fixed: The vendor has not specified an exact affected-version range as of 16 September 2026. Oracle directs customers to its patch availability documentation for installation instructions.
Source: Oracle September 2026 Critical Security Patch Update
Oracle Identity Manager
Affected: 12.2.1.4.0 and 14.1.2.1.0
Fixed: The vendor has not specified an exact affected-version range as of 16 September 2026. Oracle directs customers to its patch availability documentation for installation instructions.
Source: Oracle September 2026 Critical Security Patch Update
Oracle Access Manager
Affected: 12.2.1.4.0 and 14.1.2.1.0 for CVE-2026-71133, CVE-2026-71163, CVE-2026-73940, CVE-2026-73944, CVE-2026-73945, CVE-2026-73946, CVE-2026-73950 and CVE-2026-73962. 12.2.1.4.0 and 14.1.2.0.0 for CVE-2026-73947.
Fixed: The vendor has not specified an exact affected-version range as of 16 September 2026. Oracle directs customers to its patch availability documentation for installation instructions.
Source: Oracle September 2026 Critical Security Patch Update
Oracle WebCenter Portal
Affected: 12.2.1.4.0 and 14.1.2.0.0
Fixed: The vendor has not specified an exact affected-version range as of 16 September 2026. Oracle directs customers to its patch availability documentation for installation instructions.
Source: Oracle September 2026 Critical Security Patch Update
Oracle JDeveloper
Affected: 12.2.1.4.0 and 14.1.2.0.0
Fixed: The vendor has not specified an exact affected-version range as of 16 September 2026. Oracle directs customers to its patch availability documentation for installation instructions.
Source: Oracle September 2026 Critical Security Patch Update
Vulnerability Breakdown
CVE-2026-71133 - Oracle Access Manager Authentication Engine
Severity: Critical
CVSS: 10.0
Description: A remotely exploitable Oracle Access Manager vulnerability over HTTP.
Impact: Successful exploitation can result in takeover of Oracle Access Manager.
Conditions: No authentication required.
Source: Oracle September 2026 Critical Security Patch Update
CVE-2026-71163 - Oracle Access Manager Authentication Engine
Severity: Critical
CVSS: 9.9
Description: A network-accessible Access Manager vulnerability.
Impact: It can enable unauthorised access to, or modification of, critical data and partial denial of service.
Conditions: Low-privileged access is required.
Source: Oracle September 2026 Critical Security Patch Update
CVE-2026-73945 - Oracle Access Manager Authentication Engine
Severity: Critical
CVSS: 9.9
Description: A network-accessible Access Manager vulnerability over HTTP.
Impact: Successful exploitation can result in takeover of Oracle Access Manager.
Conditions: Low-privileged access is required.
Source: Oracle September 2026 Critical Security Patch Update
CVE-2026-73948 - Oracle WebCenter Portal Composer
Severity: Critical
CVSS: 9.9
Description: A network-accessible WebCenter Portal vulnerability over HTTP.
Impact: Successful exploitation can result in takeover of Oracle WebCenter Portal.
Conditions: Low-privileged access is required.
Source: Oracle September 2026 Critical Security Patch Update
CVE-2026-70748 - Oracle WebLogic Server Core
Severity: Critical
CVSS: 9.8
Description: A remotely exploitable WebLogic Server Core vulnerability over T3 or IIOP.
Impact: Successful exploitation can result in takeover of Oracle WebLogic Server.
Conditions: No authentication required.
Source: Oracle September 2026 Critical Security Patch Update
CVE-2026-70756 - Oracle WebLogic Server Core
Severity: Critical
CVSS: 9.8
Description: A remotely exploitable WebLogic Server Core vulnerability over T3 or IIOP.
Impact: Successful exploitation can result in takeover of Oracle WebLogic Server.
Conditions: No authentication required.
Source: Oracle September 2026 Critical Security Patch Update
CVE-2026-70757 - Oracle WebLogic Server Core
Severity: Critical
CVSS: 9.8
Description: A remotely exploitable WebLogic Server Core vulnerability over T3 or IIOP.
Impact: Successful exploitation can result in takeover of Oracle WebLogic Server.
Conditions: No authentication required.
Source: Oracle September 2026 Critical Security Patch Update
CVE-2026-70913 - Oracle Identity Manager Core
Severity: Critical
CVSS: 9.8
Description: A remotely exploitable Identity Manager Core vulnerability over HTTP.
Impact: Successful exploitation can result in takeover of Oracle Identity Manager.
Conditions: No authentication required.
Source: Oracle September 2026 Critical Security Patch Update
CVE-2026-73940 - Oracle Access Manager Authentication Engine
Severity: Critical
CVSS: 9.8
Description: A remotely exploitable Access Manager vulnerability over T3 or IIOP.
Impact: Successful exploitation can result in takeover of Oracle Access Manager.
Conditions: No authentication required.
Source: Oracle September 2026 Critical Security Patch Update
CVE-2026-73947 - Oracle Access Manager Authentication Engine
Severity: Critical
CVSS: 9.8
Description: A remotely exploitable Access Manager vulnerability over HTTP.
Impact: Successful exploitation can result in takeover of Oracle Access Manager.
Conditions: No authentication required.
Source: Oracle September 2026 Critical Security Patch Update
CVE-2026-73950 - Oracle Access Manager Authentication Engine
Severity: Critical
CVSS: 9.8
Description: A remotely exploitable Access Manager vulnerability over HTTP.
Impact: Successful exploitation can result in takeover of Oracle Access Manager.
Conditions: No authentication required.
Source: Oracle September 2026 Critical Security Patch Update
CVE-2026-73953 - Oracle WebCenter Portal Portlet Services
Severity: Critical
CVSS: 9.8
Description: A remotely exploitable WebCenter Portal vulnerability over HTTP.
Impact: Successful exploitation can result in takeover of Oracle WebCenter Portal.
Conditions: No authentication required.
Source: Oracle September 2026 Critical Security Patch Update
CVE-2026-73956 - Oracle WebCenter Portal Composer
Severity: Critical
CVSS: 9.8
Description: A remotely exploitable WebCenter Portal vulnerability over HTTP.
Impact: Successful exploitation can result in takeover of Oracle WebCenter Portal.
Conditions: No authentication required.
Source: Oracle September 2026 Critical Security Patch Update
CVE-2026-73961 - Oracle JDeveloper ADF Faces
Severity: Critical
CVSS: 9.8
Description: A remotely exploitable JDeveloper vulnerability over HTTP.
Impact: Successful exploitation can result in takeover of Oracle JDeveloper.
Conditions: No authentication required.
Source: Oracle September 2026 Critical Security Patch Update
CVE-2026-73963 - Oracle WebCenter Portal Portlet Services
Severity: Critical
CVSS: 9.8
Description: A remotely exploitable WebCenter Portal vulnerability over HTTP.
Impact: Successful exploitation can result in takeover of Oracle WebCenter Portal.
Conditions: No authentication required.
Source: Oracle September 2026 Critical Security Patch Update
CVE-2026-73962 - Oracle Access Manager Authentication Engine
Severity: Critical
CVSS: 9.6
Description: A network-accessible Access Manager vulnerability over HTTPS.
Impact: It can enable unauthorised access to, or modification of, critical data.
Conditions: Low-privileged access is required.
Source: Oracle September 2026 Critical Security Patch Update
CVE-2026-73957 - Oracle WebCenter Portal Portlet Services
Severity: Critical
CVSS: 9.3
Description: A remotely exploitable WebCenter Portal vulnerability over HTTP.
Impact: It can enable unauthorised access to, or modification of, critical data.
Conditions: No authentication is required, but user interaction by someone other than the attacker is required.
Source: Oracle September 2026 Critical Security Patch Update
CVE-2026-73944 - Oracle Access Manager Authentication Engine
Severity: Critical
CVSS: 9.1
Description: A remotely exploitable Access Manager vulnerability over HTTP.
Impact: It can enable unauthorised access to, or modification of, critical data.
Conditions: No authentication required.
Source: Oracle September 2026 Critical Security Patch Update
CVE-2026-73946 - Oracle Access Manager Authentication Engine
Severity: Critical
CVSS: 9.1
Description: A network-accessible Access Manager vulnerability over HTTP.
Impact: Successful exploitation can result in takeover of Oracle Access Manager.
Conditions: High-privileged access is required.
Source: Oracle September 2026 Critical Security Patch Update
CVE-2026-73952 - Oracle WebCenter Portal Portlet Services
Severity: Critical
CVSS: 9.1
Description: A remotely exploitable WebCenter Portal vulnerability over HTTP.
Impact: It can enable unauthorised access to, or modification of, critical data.
Conditions: No authentication required.
Source: Oracle September 2026 Critical Security Patch Update
Mitigation
Apply the applicable Oracle September 2026 Critical Security Patch Update to every affected, supported Fusion Middleware deployment as soon as possible. Use Oracle's patch availability documentation and test changes in a non-production environment before deployment.
Until Oracle patches are applied, reduce exposure by blocking the network protocols required by an attack where operationally feasible. Review unnecessary privileges and access to affected packages. These are temporary risk-reduction measures, not fixes.
Summary for IT Teams
Products: Oracle WebLogic Server, Oracle Identity Manager, Oracle Access Manager, Oracle WebCenter Portal and Oracle JDeveloper
Threat Level: Critical, with CVSS scores up to 10.0.
Action Required: Identify affected versions and apply Oracle's September 2026 patches. Restrict unnecessary exposure to HTTP, HTTPS, T3 and IIOP interfaces while patching is planned and tested.
Reference
Need Help?
Secure ISS can help assess exposure, validate affected versions and plan remediation for Oracle Fusion Middleware environments. Contact us on 1300 769 460 or email our team.

