Critical severity9.8CISA KEVNVD Advisory· Published Jun 11, 2026· Updated Jun 12, 2026
CVE-2026-35273
CVE-2026-35273
Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.61:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.61:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.62:*:*:*:*:*:*:*
- (no CPE)range: 8.61, 8.62
Patches
Vulnerability mechanics
References
2- www.cisa.gov/known-exploited-vulnerabilities-catalognvdThird Party AdvisoryUS Government Resource
- www.oracle.com/security-alerts/alert-cve-2026-35273.htmlnvdVendor Advisory
News mentions
37- ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More StoriesThe Hacker News · Jul 16, 2026
- Over 900 Oracle E-Business instances exposed to ongoing attacksBleepingComputer · Jul 1, 2026
- Nissan Traces Data Breach to PeopleSoft Zero-Day ExploitGovInfoSecurity · Jun 30, 2026
- Nissan Discloses Employee Data Breach Linked to Oracle Zero-DayInfosecurity Magazine · Jun 30, 2026
- Nissan Employee Data Breached in Oracle PeopleSoft HackSecurityWeek · Jun 30, 2026
- Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the WildThe Hacker News · Jun 30, 2026
- Nissan Confirms Data Breach Following Oracle PeopleSoft 0-Day AttacksCyber Security News · Jun 30, 2026
- Nissan discloses employee data breach linked to Oracle zero-day attacksBleepingComputer · Jun 29, 2026
- NAIC says public data stolen in ShinyHunters' PeopleSoft breachBleepingComputer · Jun 29, 2026
- Hackers now exploit critical Oracle E-Business flaw in attacksBleepingComputer · Jun 29, 2026
- Insurance Regulators Group NAIC Hit in Oracle PeopleSoft HackSecurityWeek · Jun 29, 2026
- ZDI-26-389: Oracle PeopleSoft ExecuteProcessActivityCommand External Control of File Path Remote Code Execution VulnerabilityZero Day Initiative · Jun 24, 2026
- ZDI-26-388: Oracle PeopleSoft HubMBeanPersistance Deserialization of Untrusted Data Remote Code Execution VulnerabilityZero Day Initiative · Jun 24, 2026
- ZDI-26-387: Oracle PeopleSoft HttpListeningConnector Server-Side Request Forgery VulnerabilityZero Day Initiative · Jun 24, 2026
- Oracle June 2026 Critical Security Patch Update Addresses 243 CVEs (CVE-2026-35273)Tenable Blog · Jun 18, 2026
- PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVMTrend Micro Research · Jun 18, 2026
- CISA Warns of Oracle PeopleSoft 0-Day Vulnerability Exploited in Ransomware AttacksCyber Security News · Jun 17, 2026
- Oracle’s Second Monthly Security Updates Deliver 245 PatchesSecurityWeek · Jun 17, 2026
- ShinyHunters Hits Universities Via Oracle Zero-DayGovInfoSecurity · Jun 16, 2026
- Council of Europe hacked in ShinyHunters' PeopleSoft heistThe Register Security · Jun 15, 2026
- ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and MoreThe Hacker News · Jun 15, 2026
- 15th June – Threat Intelligence ReportCheck Point Research · Jun 15, 2026
- Week in review: Exploited Check Point VPN zero-day, Oracle PeopleSoft servers under attackHelp Net Security · Jun 14, 2026
- ShinyHunters Uses Oracle Zero-Day to Rampage Higher EdDark Reading · Jun 12, 2026
- ShinyHunters is actively extorting universities after exploiting an unpatched Oracle flawCyberScoop · Jun 12, 2026
- Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)Rapid7 Blog · Jun 12, 2026
- Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHuntersSecurityWeek · Jun 12, 2026
- Oracle PeopleSoft 0-Day RCE Vulnerability Exploited in Attacks by ShinyHuntersCyber Security News · Jun 12, 2026
- Oracle CVE-2026-35273 Added to CISA KEV Under Active Ransomware ExploitationVypr Intelligence · Jun 12, 2026
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach UniversitiesThe Hacker News · Jun 11, 2026
- Oracle mitigates PeopleSoft zero-day exploited in data theft attacksBleepingComputer · Jun 11, 2026
- ShinyHunters hacked 100+ orgs by exploiting an Oracle PeopleSoft 0-dayThe Register Security · Jun 11, 2026
- Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day AttacksSecurityWeek · Jun 11, 2026
- Oracle PeopleSoft servers under attack, Oracle pushes out-of-band security alertHelp Net Security · Jun 11, 2026
- Oracle Emergency Security Update to Fix Critical RCE VulnerabilityCyber Security News · Jun 11, 2026
- ShinyHunters Targets Education Sector with Oracle PeopleSoft ExploitMandiant Threat Intelligence · Jun 11, 2026
- CISA Adds One Known Exploited Vulnerability to CatalogCISA Alerts