OFFSEC · Offensive Security

Oracle went monthly and shipped 673 patches. The flaw being exploited was fixed in January.

The September update carries six maximum-severity flaws, none yet exploited. Meanwhile CVE-2026-21962, patched eight months ago, drew more than 140,000 recorded attacks and was catalogued as exploited only in August.

What shipped

Oracle released 673 new security patches on 15 September 2026 across its product families [1]. Fusion Middleware accounted for 153 of them [2]. Six carry the maximum CVSS rating of 10.0, in Access Manager, Forms, Internet Directory, Platform Security for Java, WebLogic Server and Hyperion Financial Management, with a further thirteen at 9.9 [2]. Every maximum-severity flaw is remotely exploitable without authentication and requires no user interaction, and none was documented as exploited in the wild at announcement [2].

The most useful sentence in the advisory is Oracle's own standing warning: it continues to receive reports of attempts to exploit vulnerabilities for which patches have already been released, and in some cases attackers succeeded because the targeted customers had failed to apply them [1].

The cadence change

Oracle has shifted from quarterly to monthly patching, and cautions that skipping any monthly release should not be assumed covered by a later one, so teams must review all prior releases for coverage [2]. That is a material change to a maintenance model many organisations built around four fixed dates a year.

The practical consequence falls on regression testing. A quarterly cycle left a window between releases in which a middleware patch could be certified against an application stack. A monthly cycle does not, for any estate where a Fusion Middleware update means re-validating the applications sitting on top of it. The likely outcome is not twelve-times-a-year patching. It is a widening gap between the patch level Oracle publishes and the patch level estates actually run.

The volume context is not Oracle-specific. In the same month Microsoft shipped 972 new CVEs, 997 including external and Chromium issues, of which 114 were rated critical [10]. The Zero Day Initiative's assessment is that patch volumes keep rising without a corresponding spike in active exploitation, that AI-assisted vulnerability discovery shows no sign of slowing, and that this level of output is the new normal [10].

The flaw that is actually being exploited

CVE-2026-21962 affects Oracle HTTP Server and the WebLogic Server Proxy Plug-in at CVSS 10.0 [3][7]. It is an access-control failure: a crafted request bypasses the proxy layer's authorisation evaluation and reaches protected backend resources without credentials [3]. Affected builds are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0, together with the IIS plug-in at 12.2.1.4.0 [3][7].

The timeline is the argument [5]. Oracle patched on 20 January 2026. Public exploit code appeared on GitHub on 22 January, and a honeypot recorded the first attack the same day. Broader internet scanning began on 27 January. Across the twelve days to 3 February, Imperva and CloudSEK documented more than 140,000 attacks, averaging roughly 11,700 a day, against targets in 21 countries with about 75% aimed at United States infrastructure, launched from infrastructure in nine source countries [5].

Attackers used automated scanning and rented cloud infrastructure, including from DigitalOcean [6]. More than 1,500 internet-facing WebLogic servers remained vulnerable months after the patch shipped [5]. The Hacker News reports the flaw among those used by China-linked actors to deliver the SNOWLIGHT downloader across government and commercial networks in more than 100 countries [4], and Aardwolf reports a China-linked group targeting government systems with it by August [6]. Those are the outlets' characterisations.

CISA added it to the Known Exploited Vulnerabilities catalogue on 24 August 2026 [3], with a federal remediation deadline of 27 August under Binding Operational Directive 26-04 [4]. Seven months after a fix existed, and seven months after exploitation began.

A regulator published it twice

Singapore's Cyber Security Agency issued an advisory on CVE-2026-21962 on 22 January 2026, stating that successful exploitation could allow an unauthenticated attacker with HTTP network access to gain access to data or full access, and advising immediate updates [7]. It issued a second advisory on the same CVE on 26 August, this time noting that the vulnerability was reportedly being actively exploited and that a proof-of-concept exploit was publicly available [8].

A national agency publishing twice on one vulnerability, seven months apart, measures absorption rather than disclosure. The information was complete on day one. The second advisory exists because the first did not produce enough patching. It is also the clearest regional signal in the record on this flaw, and it came from a regulator rather than from vendor telemetry.

There is a second maximum-severity WebLogic flaw

CVE-2026-35301 sits in the WebLogic Console component at CVSS 10.0, classified as CWE-306, missing authentication for a critical function. It affects 12.2.1.4.0 and 14.1.1.0.0 and was fixed in the June 2026 Critical Patch Update [9]. Unauthenticated network access to the Console, typically on ports 7001 and 7002, yields full compromise with scope extending beyond the server itself [9].

Two separate unauthenticated CVSS 10.0 paths into the same product family within six months is the shape of the problem. Neither requires a novel technique. Both require the Console or the proxy layer to be reachable from somewhere an attacker can scan.

What to do

  • Establish the January and June patch levels before assessing September. Oracle's warning that monthly releases are not cumulative in effect [2] means an earlier gap is not closed by installing the newest update.
  • Take the WebLogic Console off the internet. Restrict it to management networks reachable through VPN or a bastion, disable it where unused, and firewall ports 7001 and 7002 [9].
  • Hunt retrospectively rather than only forward. Review logs from January onward for requests that reached console or admin paths the proxy should have blocked, particularly those with unusual URL structures or path obfuscation [3][6].
  • Assume exposure where the fix is old. A flaw patched in January, exploited from January and catalogued in August describes a population compromised long before it was warned.
  • Decide the monthly operating model now: which product families get same-month application, which get a standing exception with compensating controls, and who signs that exception. It is easier settled in advance than mid-cycle.

Domain view

The binding constraint in this domain has moved. Patch availability is not the bottleneck, and has not been for some time: Oracle shipped 673 fixes in one month and Microsoft close to a thousand [1][10]. Absorption is the bottleneck, and the volume of patches is now itself one of the obstacles to absorbing them.

The evidence sits in the gap between the two halves of this article. The six maximum-severity flaws announced in September are not being exploited. The one that is has been fixed since January and catalogued since August, and still left more than 1,500 servers reachable [5][3]. Attention follows announcements; exploitation follows exposure, and the two are months out of phase.

For operators in this region the practical read is the CSA sequence [7][8]. Two advisories on one CVE, seven months apart, the second effectively an acknowledgement that the first was not enough. Any organisation running Oracle middleware should be able to state today which Critical Patch Update its estate is actually at. For most, producing that answer takes longer than it should, and that interval is the real measure of exposure.

Sources

Every R3KONX article cites its primary material. 10 sources, in order of first citation. Links open the original publication.

  1. Oracle Critical Security Patch Update Advisory - September 2026 Oracle · 2026-09-15
  2. Oracle's September patches put Fusion Middleware back in the hot seat daily.dev · 2026-09
  3. CVE-2026-21962: Oracle HTTP Server and WebLogic Proxy Access Control Flaw Decryption Digest · 2026-08
  4. Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data The Hacker News · 2026-08
  5. WebLogic CVE-2026-21962: 140K Attacks, Patch Now Shattered.io · 2026
  6. A Maximum-Severity Oracle WebLogic Flaw Is Being Exploited Right Now Aardwolf Security · 2026
  7. Critical Vulnerability in Oracle Products (AL-2026-006) Cyber Security Agency of Singapore · 2026-01-22
  8. Active Exploitation of Vulnerability in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-In (AL-2026-111) Cyber Security Agency of Singapore · 2026-08-26
  9. CVE-2026-35301: Oracle WebLogic Server RCE Vulnerability SentinelOne · 2026
  10. The September 2026 Security Update Review Zero Day Initiative · 2026-09-08

Researched and written by the R3KONX Analysis Desk from the cited primary material, with AI assistance in research and drafting. Methodological caveat: attack-volume figures come from vendor honeypot and telemetry networks with differing visibility and are cited to their source; product naming for the affected plug-ins varies between write-ups and the vendor advisory is authoritative. Actor characterisations are the reporting outlets' assessments, not independent R3KONX findings. Corrections to event@r3konx.asia.

R3KONX 2027

Work in this domain? So does the programme

4–6 May 2027, World Trade Centre Kuala Lumpur. Curated talks, hands-on training and The BattleGrid.