☕ This Week’s Focus
Wednesday’s tax update lands on top of September’s CSPU. Stacked calendars are the leadership problem.
Tax Update 26-C is still aimed at Wednesday, September 30 — delivered through the HCM Weekly PRP, not an Image. Thirteen days earlier, Oracle shipped the September CSPU: 673 patches, PeopleSoft row 16 / 4 unauthenticated. Next cumulative security Tuesday is October 20 (CPU).
Most shops are still proving September is installed. Payroll cannot wait for that argument to finish. That is not a PeopleSoft problem. That is a change-window capacity problem.
Let’s get into it.
🔐 Score Is Not Exposure — Order the Work by Reachability
🔗 Oracle’s September 2026 CSPU: 673 security patches (Marc-Frédéric Gomez) https://blog.marcfredericgomez.com/oracles-september-2026-cspu-673-security-patches/
September 16, 2026. Independent teardown of Rev 1. Headline numbers match Oracle: 673 patches across 16 product families / 17 matrices; 247 remotely exploitable without authentication (36.7% — sum of matrix openers, not a vendor total). Six CVEs at 10.0. PeopleSoft row in his table: 16 patches, 4 remote-without-auth, top score 8.8. Closing rule worth putting on the CAB whiteboard: the column that orders the work is not the score — it is protocol + unauthenticated exploitation, crossed with what is actually reachable.
🔗 Oracle Critical Security Patch Update Advisory — September 2026 (Oracle) https://www.oracle.com/security-alerts/cspusep2026.html
Still Rev 1, initial release 2026-09-15. PeopleSoft executive summary unchanged: 16 new security patches; 4 remotely exploitable without authentication. PeopleTools 8.61–8.63 still named. Next four security Tuesdays from the same page and the security-alerts calendar: 20 October 2026 (CPU), 17 November 2026 (CSPU), 15 December 2026 (CSPU), 19 January 2027 (CPU).
🔗 Oracle September 2026 CSPU — 672 CVEs, 104 Critical (ThreatAft) https://threataft.com/articles/oracle-september-2026-cspu-mass-disclosure
September 16, 2026. Tally aligns with Tenable’s cut: 672 unique CVEs in 673 patches; 104 critical (15.5%); high severity 74.7%. Priority callout sits on Fusion Middleware identity/runtime (Access Manager, WebLogic T3/IIOP, Internet Directory) — useful if your PeopleSoft estate still trusts those layers.
🔗 Oracle critical patch updates highlights growing patch fatigue (The IT Nerd / Tyler Reguly, Fortra) https://itnerd.blog/2026/09/16/oracle-critical-patch-updates-highlights-growing-patch-fatigue/
September 16, 2026. Reguly’s framing: patch-everything vs patch-minimally vs prioritize-then-patch camps are colliding while monthly volume stays high. Practical test he cites from CISA BOD 26-04: publicly exposed, on the KEV list, automatable, complete control. Also blunt on Oracle complexity — tooling that cannot inventory assets and patch level is the wrong axe.
My read: Ed.37 named the doors (Business Interlink CVE-2026-73954 at 8.1 unauth, Ren Server CVE-2026-73960 at 7.5 unauth, Integration Broker CVE-2026-87264 at 7.7). This week the argument is sequencing. If your CAB still sorts by CVSS alone, you will patch the loud score and miss the reachable row. October 20 is cumulative — everything you deferred in May–September rides into a heavier qualification cycle.
💸 Wednesday Is Payroll — Sep 30 Does Not Move for Your CSPU Backlog
🔗 PeopleSoft Payroll for North America Tax Update 26-C Delivery Moves to September (Oracle / Anne Leung) https://blogs.oracle.com/peoplesoft/peoplesoft-payroll-for-north-america-tax-update-26-c-delivery-moves-to-september
August 20, 2026. Tax Update 26-C targeted for Wednesday, September 30, 2026 through the HCM Weekly PeopleSoft Release Patchset. HCM Image 56 (November target) carries Tax Update 26-D (first year-end set). Weekly HCM PRPs continue through December 2026 and January 2027 — regular HCM patches that also carry Payroll for North America updates, not a separate tax package. Bookmark MOS FAQ2322. Advisor webcast usually one to two weeks after delivery (KB168951).
🔗 Preparing PeopleSoft Suppliers for 2026 1099 Reporting (Oracle / Alicia Kinsey) https://blogs.oracle.com/peoplesoft/preparing-peoplesoft-suppliers-for-2026-1099-reporting
August 13, 2026. For suppliers marked for Withholding with TIN Type SSN, populate Withholding Name 1 / Name 2 as first / last name on a new effective-dated address row. Required for IRS IRIS. Bulk path: ExcelToCI via VNDR_ID_EXCEL; rerun TIN Matching after updates. Bookmark KB878101.
🔗 Critical Patch Updates, Critical Security Patch Updates, Security Alerts and Bulletins (Oracle) https://www.oracle.com/security-alerts/
Confirms the next quarterly CPU: 20 October 2026. Pre-release announcement publishes the Thursday before. September CSPU remains at Rev 1 as of this writing; August reached Rev 4 in seventeen days — watch for revisions.
My read: Sep 15 was security Tuesday. Sep 30 is payroll Wednesday. Oct 20 is the cumulative CPU. Three different owners usually fight for the same two change windows. If your whiteboard only tracks Images, all three arrive as emergencies.
🤖 Agentic AI Needs Decision Rights Before It Touches ERP Data
🔗 Five Decision Rights CIOs Need for Agentic AI (Architecture & Governance / Sanjeeve Kumar Gajadi) https://www.architectureandgovernance.com/artificial-intelligence/five-decision-rights-cios-need-for-agentic-ai/
September 25, 2026. Practical matrix for production agents: authorization, data access, human intervention, exception handling, accountability — each with a named owner, enforceable control, and reviewable evidence. Explicitly maps to NIST AI RMF, ISO/IEC 42001, and EU AI Act oversight expectations. Core test on authorization: can you explain why the agent was allowed to perform each consequential action?
🔗 How CIOs Can Govern AI Agents at Scale in 2026 (BCG) https://www.bcg.com/publications/2026/how-cios-govern-ai-agents-at-scale
August 14, 2026. Enterprise AI Control Plane framing: identity, agent/tool registry, runtime policy enforcement, and “golden path” deployment harnesses so the compliant route is the fast one. Failure mode named cleanly — platform-by-platform governance duplicates effort and leaves shadow agents.
My read: PeopleTools 8.63 shipped GenAI options into the same release train that still carries CSPU rows. Before an agent reads or writes payroll, supplier, or IB payloads, name the five rights. “We have a policy” is not the same sentence as “we can stop it, prove who authorized it, and roll it back.”
🧭 Oracle’s Capex Story Is Not Your Patch Calendar — Keep the Columns Separate
🔗 Oracle Announces Q1 Results Driven by Triple Digit Growth in Cloud Infrastructure Revenues (Oracle / PR Newswire) https://www.prnewswire.com/news-releases/oracle-announces-q1-results-driven-by-triple-digit-growth-in-cloud-infrastructure-revenues-302875728.html
September 10, 2026. Q1 FY27: total revenue $19.3B (+30%); Cloud Infrastructure $7.4B (+121%); Cloud Applications $4.2B (+10%); software revenues −3% to $5.5B; Remaining Performance Obligations $664B (+$209B YoY). More than $30B additional AI cloud contracts booked in the quarter; 850MW additional datacenter capacity; 300,000+ GPUs delivered.
My read: Useful board context for hosting and capacity conversations. Useless as a reason to skip Wednesday’s tax PRP or Tuesday’s matrix. Keep OCI growth in the infrastructure column. Keep CSPU / 26-C / IRIS in the operations column.
💬 Aaron’s Take
The vendor published three clocks that all land inside four weeks. Four concrete things:
Prove September CSPU is installed on every 8.61 / 8.62 / 8.63 environment before you argue about 26-C sequencing. Start with the unauthenticated PeopleSoft rows (Business Interlink CVE-2026-73954, Ren Server CVE-2026-73960), then Integration Broker (CVE-2026-87264). Order remaining work by reachability, not CVSS alone.
Treat Sep 30 as a hard payroll window. 26-C rides a Weekly PRP. Bookmark FAQ2322. Put it on the same whiteboard as Sep 15 and Oct 20.
Do not let IRIS wait for January. Withholding Name 1/2 for SSN TIN types; new IRIS TCC (45+ days); A2A PeopleTools floors are published. Bookmark KB878101.
If AI agents will touch ERP data, assign the five decision rights in writing this week — authorization, data access, human intervention, exception handling, accountability — with named owners and kill-switch evidence.
This is not a “PeopleSoft is old” problem. It is a change-calendar and attack-surface problem. Support runway buys time. It does not buy a free pass on Wednesday’s PRP.
🌐 Join the Community
Subscribe to PeopleSoft Cloud for the Monday Digest — no vendor spin, just what changed and what to do about it.
✅ Monday: what moved in the PeopleSoft, Oracle and ERP world, with a read on why it matters
✅ Written by a practitioner who still has to make the change window


