T

Threats

Oracle Fusion Middleware Critical Vulnerabilities

Overview

  • CVE: CVE-2026-70748, CVE-2026-70756, CVE-2026-70757, CVE-2026-70913, CVE-2026-71133, CVE-2026-71163, CVE-2026-73940, CVE-2026-73944, CVE-2026-73945, CVE-2026-73946, CVE-2026-73947, CVE-2026-73948, CVE-2026-73950, CVE-2026-73952, CVE-2026-73953, CVE-2026-73956, CVE-2026-73957, CVE-2026-73961, CVE-2026-73962, CVE-2026-73963

  • Severity: Critical

  • Date: 16 September 2026

Oracle has released its September 2026 Critical Security Patch Update, including fixes for 20 critical vulnerabilities in Oracle Fusion Middleware products. The affected Oracle components are exposed through HTTP, HTTPS, T3 or IIOP depending on the CVE. Many can be exploited remotely without authentication and can result in product takeover or unauthorised access to critical data.

Affected Versions

Oracle WebLogic Server

Affected: 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0

Fixed: The vendor has not specified an exact affected-version range as of 16 September 2026. Oracle directs customers to its patch availability documentation for installation instructions.

Source: Oracle September 2026 Critical Security Patch Update

Oracle Identity Manager

Affected: 12.2.1.4.0 and 14.1.2.1.0

Fixed: The vendor has not specified an exact affected-version range as of 16 September 2026. Oracle directs customers to its patch availability documentation for installation instructions.

Source: Oracle September 2026 Critical Security Patch Update

Oracle Access Manager

Affected: 12.2.1.4.0 and 14.1.2.1.0 for CVE-2026-71133, CVE-2026-71163, CVE-2026-73940, CVE-2026-73944, CVE-2026-73945, CVE-2026-73946, CVE-2026-73950 and CVE-2026-73962. 12.2.1.4.0 and 14.1.2.0.0 for CVE-2026-73947.

Fixed: The vendor has not specified an exact affected-version range as of 16 September 2026. Oracle directs customers to its patch availability documentation for installation instructions.

Source: Oracle September 2026 Critical Security Patch Update

Oracle WebCenter Portal

Affected: 12.2.1.4.0 and 14.1.2.0.0

Fixed: The vendor has not specified an exact affected-version range as of 16 September 2026. Oracle directs customers to its patch availability documentation for installation instructions.

Source: Oracle September 2026 Critical Security Patch Update

Oracle JDeveloper

Affected: 12.2.1.4.0 and 14.1.2.0.0

Fixed: The vendor has not specified an exact affected-version range as of 16 September 2026. Oracle directs customers to its patch availability documentation for installation instructions.

Source: Oracle September 2026 Critical Security Patch Update

Vulnerability Breakdown

CVE-2026-71133 - Oracle Access Manager Authentication Engine

Severity: Critical
CVSS: 10.0
Description: A remotely exploitable Oracle Access Manager vulnerability over HTTP.
Impact: Successful exploitation can result in takeover of Oracle Access Manager.
Conditions: No authentication required.
Source: Oracle September 2026 Critical Security Patch Update

CVE-2026-71163 - Oracle Access Manager Authentication Engine

Severity: Critical
CVSS: 9.9
Description: A network-accessible Access Manager vulnerability.
Impact: It can enable unauthorised access to, or modification of, critical data and partial denial of service.
Conditions: Low-privileged access is required.
Source: Oracle September 2026 Critical Security Patch Update

CVE-2026-73945 - Oracle Access Manager Authentication Engine

Severity: Critical
CVSS: 9.9
Description: A network-accessible Access Manager vulnerability over HTTP.
Impact: Successful exploitation can result in takeover of Oracle Access Manager.
Conditions: Low-privileged access is required.
Source: Oracle September 2026 Critical Security Patch Update

CVE-2026-73948 - Oracle WebCenter Portal Composer

Severity: Critical
CVSS: 9.9
Description: A network-accessible WebCenter Portal vulnerability over HTTP.
Impact: Successful exploitation can result in takeover of Oracle WebCenter Portal.
Conditions: Low-privileged access is required.
Source: Oracle September 2026 Critical Security Patch Update

CVE-2026-70748 - Oracle WebLogic Server Core

Severity: Critical
CVSS: 9.8
Description: A remotely exploitable WebLogic Server Core vulnerability over T3 or IIOP.
Impact: Successful exploitation can result in takeover of Oracle WebLogic Server.
Conditions: No authentication required.
Source: Oracle September 2026 Critical Security Patch Update

CVE-2026-70756 - Oracle WebLogic Server Core

Severity: Critical
CVSS: 9.8
Description: A remotely exploitable WebLogic Server Core vulnerability over T3 or IIOP.
Impact: Successful exploitation can result in takeover of Oracle WebLogic Server.
Conditions: No authentication required.
Source: Oracle September 2026 Critical Security Patch Update

CVE-2026-70757 - Oracle WebLogic Server Core

Severity: Critical
CVSS: 9.8
Description: A remotely exploitable WebLogic Server Core vulnerability over T3 or IIOP.
Impact: Successful exploitation can result in takeover of Oracle WebLogic Server.
Conditions: No authentication required.
Source: Oracle September 2026 Critical Security Patch Update

CVE-2026-70913 - Oracle Identity Manager Core

Severity: Critical
CVSS: 9.8
Description: A remotely exploitable Identity Manager Core vulnerability over HTTP.
Impact: Successful exploitation can result in takeover of Oracle Identity Manager.
Conditions: No authentication required.
Source: Oracle September 2026 Critical Security Patch Update

CVE-2026-73940 - Oracle Access Manager Authentication Engine

Severity: Critical
CVSS: 9.8
Description: A remotely exploitable Access Manager vulnerability over T3 or IIOP.
Impact: Successful exploitation can result in takeover of Oracle Access Manager.
Conditions: No authentication required.
Source: Oracle September 2026 Critical Security Patch Update

CVE-2026-73947 - Oracle Access Manager Authentication Engine

Severity: Critical
CVSS: 9.8
Description: A remotely exploitable Access Manager vulnerability over HTTP.
Impact: Successful exploitation can result in takeover of Oracle Access Manager.
Conditions: No authentication required.
Source: Oracle September 2026 Critical Security Patch Update

CVE-2026-73950 - Oracle Access Manager Authentication Engine

Severity: Critical
CVSS: 9.8
Description: A remotely exploitable Access Manager vulnerability over HTTP.
Impact: Successful exploitation can result in takeover of Oracle Access Manager.
Conditions: No authentication required.
Source: Oracle September 2026 Critical Security Patch Update

CVE-2026-73953 - Oracle WebCenter Portal Portlet Services

Severity: Critical
CVSS: 9.8
Description: A remotely exploitable WebCenter Portal vulnerability over HTTP.
Impact: Successful exploitation can result in takeover of Oracle WebCenter Portal.
Conditions: No authentication required.
Source: Oracle September 2026 Critical Security Patch Update

CVE-2026-73956 - Oracle WebCenter Portal Composer

Severity: Critical
CVSS: 9.8
Description: A remotely exploitable WebCenter Portal vulnerability over HTTP.
Impact: Successful exploitation can result in takeover of Oracle WebCenter Portal.
Conditions: No authentication required.
Source: Oracle September 2026 Critical Security Patch Update

CVE-2026-73961 - Oracle JDeveloper ADF Faces

Severity: Critical
CVSS: 9.8
Description: A remotely exploitable JDeveloper vulnerability over HTTP.
Impact: Successful exploitation can result in takeover of Oracle JDeveloper.
Conditions: No authentication required.
Source: Oracle September 2026 Critical Security Patch Update

CVE-2026-73963 - Oracle WebCenter Portal Portlet Services

Severity: Critical
CVSS: 9.8
Description: A remotely exploitable WebCenter Portal vulnerability over HTTP.
Impact: Successful exploitation can result in takeover of Oracle WebCenter Portal.
Conditions: No authentication required.
Source: Oracle September 2026 Critical Security Patch Update

CVE-2026-73962 - Oracle Access Manager Authentication Engine

Severity: Critical
CVSS: 9.6
Description: A network-accessible Access Manager vulnerability over HTTPS.
Impact: It can enable unauthorised access to, or modification of, critical data.
Conditions: Low-privileged access is required.
Source: Oracle September 2026 Critical Security Patch Update

CVE-2026-73957 - Oracle WebCenter Portal Portlet Services

Severity: Critical
CVSS: 9.3
Description: A remotely exploitable WebCenter Portal vulnerability over HTTP.
Impact: It can enable unauthorised access to, or modification of, critical data.
Conditions: No authentication is required, but user interaction by someone other than the attacker is required.
Source: Oracle September 2026 Critical Security Patch Update

CVE-2026-73944 - Oracle Access Manager Authentication Engine

Severity: Critical
CVSS: 9.1
Description: A remotely exploitable Access Manager vulnerability over HTTP.
Impact: It can enable unauthorised access to, or modification of, critical data.
Conditions: No authentication required.
Source: Oracle September 2026 Critical Security Patch Update

CVE-2026-73946 - Oracle Access Manager Authentication Engine

Severity: Critical
CVSS: 9.1
Description: A network-accessible Access Manager vulnerability over HTTP.
Impact: Successful exploitation can result in takeover of Oracle Access Manager.
Conditions: High-privileged access is required.
Source: Oracle September 2026 Critical Security Patch Update

CVE-2026-73952 - Oracle WebCenter Portal Portlet Services

Severity: Critical
CVSS: 9.1
Description: A remotely exploitable WebCenter Portal vulnerability over HTTP.
Impact: It can enable unauthorised access to, or modification of, critical data.
Conditions: No authentication required.
Source: Oracle September 2026 Critical Security Patch Update

Mitigation

  • Apply the applicable Oracle September 2026 Critical Security Patch Update to every affected, supported Fusion Middleware deployment as soon as possible. Use Oracle's patch availability documentation and test changes in a non-production environment before deployment.

  • Until Oracle patches are applied, reduce exposure by blocking the network protocols required by an attack where operationally feasible. Review unnecessary privileges and access to affected packages. These are temporary risk-reduction measures, not fixes.

Summary for IT Teams

Products: Oracle WebLogic Server, Oracle Identity Manager, Oracle Access Manager, Oracle WebCenter Portal and Oracle JDeveloper

Threat Level: Critical, with CVSS scores up to 10.0.

Action Required: Identify affected versions and apply Oracle's September 2026 patches. Restrict unnecessary exposure to HTTP, HTTPS, T3 and IIOP interfaces while patching is planned and tested.

Reference

Need Help?

Secure ISS can help assess exposure, validate affected versions and plan remediation for Oracle Fusion Middleware environments. Contact us on 1300 769 460 or email our team.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.