Oracle Security Bulletin September 2026: INCIBE Issues Critical Alert
INCIBE-CERT has released an advisory regarding the September 2026 Oracle Security Bulletin. Rated as critical, the notice covers an extensive list of products including Helidon, Oracle Access Manager, and various banking, BI, and middleware solutions.

News summary
On 18 September 2026, INCIBE-CERT published advisory INCIBE-2026-648 concerning the September Oracle Security Bulletin, assigning it a level 5 critical importance rating. The bulletin addresses vulnerabilities across a wide range of the company's product portfolio.
Affected resources include Helidon (versions 3.0.0 to 3.2.20 and 4.0.0 to 4.5.4), Oracle Access Manager, Oracle Agile PLM, Oracle Autonomous Health Framework, Oracle BI Publisher, Oracle Business Intelligence Enterprise Edition, Oracle Coherence, and several Oracle Banking solutions, among others. The full list and specific versions are available in the INCIBE advisory and the official Oracle bulletin.
Oracle products are typically at the core of business-critical processes, such as identity management, business intelligence, product lifecycle management, and application middleware. These components are not always visible; many are integrated into third-party solutions or industry-specific ERP systems, making the identification of their presence the essential first step.
With the current trend of rapid exploitation following patch releases, a bulletin of this scale must be managed as a priority, beginning with components exposed to the Internet or those handling authentication.
Source: INCIBE-CERT — 18 September 2026
Frequently Asked Questions
- How do I know if my company uses Oracle products?
- By reviewing your software inventory and consulting with your ERP and sector-specific application providers, as many components like Java middleware or Coherence come bundled within other products.
- Where can I find the full list of affected products?
- In the INCIBE-CERT advisory INCIBE-2026-648 and the official September 2026 Oracle Security Bulletin, which provide details on all affected products and versions.
Concepts mentioned in this article: Identity management
Keeping complex business software up to date requires a structured inventory and methodology. At Seintec, we manage server and application patching with rigorous pre-testing and secure backups. Speak to our team today.
Contact SeintecRelated service
Managed IT Services
We keep your systems operational and failure-free.