Oracle has published a planned release of updates to its products (Critical Patch Update), aimed at eliminating critical issues and vulnerabilities. The September update fixes 673 vulnerabilities.
Some issues:
- 19 vulnerabilitiesin VirtualBox. The most serious problem (CVE-2026-87273) is assigned a severity level of 8.6 out of 10, another 5 problems, of which 4 are specific to Windows, are assigned a severity level of 7.8 out of 10. Judging by the severity level, these vulnerabilities allow access to the host environment from the guest system. The issues have been resolved in the release of VirtualBox 7.2.18.
- Oracle Communications products included one locally exploitable vulnerability in the MySQL server with a severity level of 6.5 out of 10.
- Among the Java SE-related issues noted three vulnerabilities in the virtual machine GraalVM, exploited remotely via HTTP (danger level 8.1 out of 10).
- In Solaris, no problems were noted in the report and corrective releases not generated.
/Reports, release notes, official announcements.