Oracle shipped 673 patches this week. No security team can apply them Monday morning.
Oracle's September 2026 Critical Patch Update fixes 800+ vulnerabilities in one release. The bottleneck isn't patching capacity — it's an unscored intake queue.
Oracle's quarterly Critical Patch Update landed this week, and it's a big one: 673 patches resolving more than 800 vulnerabilities across 17 product families. Oracle itself notes the published advisory covers 672 CVEs, with another 130-plus quietly folded into bundled fixes — pushing the real count past 800 in a single release.
More than 100 of those are critical severity. Over 240 are remotely exploitable without any authentication at all. Oracle E-Business Suite alone got 159 patches; Fusion Middleware got 153, including fixes for 78 flaws an attacker could hit from the internet with no login required.
No exploitation in the wild yet, Oracle says. But the advisory also points out, dryly, that when Oracle customers do get breached, it's usually because a patch that was already available just never got applied.
The volume is the point
Here's the thing nobody says out loud on patch Tuesday: no security team is patching 673 things this week. Not honestly, not well. The advisory arrives as one flat list, and the list is the same size whether you're a three-person IT shop running one E-Business Suite instance or a Fortune 500 running all seventeen product families.
That's not a patching-capacity problem. It's an intake problem wearing a CVE number.
Every one of those 673 entries is, functionally, a request: fix this, and fix it before something bad happens. They arrive in a single undifferentiated batch, with no ranking baked in beyond Oracle's own severity score — which tells you nothing about whether the affected component is internet-facing in your environment, whether it touches a system holding customer data, or whether you're even running that product at all.
Treat that list as a queue to work top-to-bottom, or by whichever CVE number looks scariest, and you'll spend real hours patching a low-exposure internal tool while a remotely exploitable, unauthenticated flaw in a customer-facing app sits open for another two weeks. That's not a hypothetical — it's exactly the pattern Oracle's own advisory is describing when it says breaches happen where available patches sat unapplied.
Scoring beats sorting
The fix isn't "patch faster." It's scoring before you patch at all. Severity is one input. Exploitability without authentication is another. Whether the affected system is exposed to the internet, whether it holds regulated data, whether it's a dependency three other systems trust blindly — those are inputs too, and none of them come pre-attached to a CVE number.
An org that scores incoming vulnerabilities against criteria like these before assigning work ends up patching a different subset first than one that just works the Oracle list in order — and it's the subset that actually matters. That's the same discipline that separates a project intake process with real triage from one that's just a to-do list sorted by arrival date. The request volume isn't the problem. The absence of a scoring pass before the queue forms is.
Admitura was built for exactly that step — configurable weighted criteria applied to every incoming request before it becomes someone's Tuesday, whether the request is a new project or, this week, a stack of CVEs with your name on them.
Sources: Oracle Patches 800+ Vulnerabilities in September 2026 Security Update, SecurityWeek, September 2026; Oracle Critical Security Update — 673 Vulnerabilities Patched Across Product Families, Cybersecurity News, September 2026; Oracle Critical Patch Update Advisory, September 2026.