← Blog
🛡️ Vulnerability3 July 2026

CVE-2026-35273: critical vulnerability in Oracle PeopleSoft actively exploited

CVE-2026-35273 (CVSS 9.8) affects Oracle PeopleSoft PeopleTools and is on CISA's KEV catalog. What to do today.

OCIRIA security team

CVE-2026-35273: critical vulnerability in Oracle PeopleSoft actively exploited

In short

According to the NVD entry, a critical vulnerability (CVE-2026-35273, CVSS 9.8) exists in Oracle PeopleSoft Enterprise PeopleTools, in the Updates Environment Management component of versions 8.61 and 8.62 [1]. An attacker without credentials and with network access via HTTP could exploit it easily and take full control of the system [1]. The vulnerability appears in CISA's catalog of actively exploited vulnerabilities (KEV), indicating it is already being leveraged in real attacks [2]. If your organization uses PeopleSoft PeopleTools 8.61 or 8.62, the priority today is to identify whether you have exposed instances and apply Oracle's patch without delay.

What it is and why it matters

CVE-2026-35273 is a missing authentication vulnerability in critical functions of the Updates Environment Management component of PeopleSoft Enterprise PeopleTools [1]. According to the official NVD description, this is an "easily exploitable" flaw that does not require the attacker to have an account or user interaction, and that can fully compromise the confidentiality, integrity, and availability of the system (CVSS 3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) [1]. The score of 9.8 out of 10 places it at critical severity [1]. The fact that it is included in CISA's KEV catalog confirms that this is not a theoretical risk: active exploitation has already been documented [2]. Published on June 11, 2026, it is a recent vulnerability that must be treated as urgent [1].

Who is affected

Versions 8.61 and 8.62 of Oracle PeopleSoft Enterprise PeopleTools are affected [1]. The vendor involved is Oracle [1]. Our OCIRIA intelligence radar notes that this type of system is often used for human resources and payroll management, meaning a compromise could expose sensitive employee data and internal administrative processes of the company. It's worth clarifying that this information about typical usage comes from the general context of our radar and not from a specific confirmation by Oracle about this particular case; if your company operates PeopleSoft PeopleTools in the versions noted, you should consider yourself potentially affected regardless of the functional module you use.

How to know if you are vulnerable

The first step is to confirm which version of PeopleTools you have deployed and whether it corresponds to 8.61 or 8.62 [1]. Since exploitation is carried out over the network via HTTP without requiring authentication [1], it is especially important to review which PeopleSoft instances are exposed to the internet or accessible from poorly controlled networks. We recommend checking your exposed surface to identify PeopleSoft assets visible from outside and prioritize their review. Additionally, given that active exploitation is already recorded in KEV [2], it is advisable to review the access logs of your PeopleSoft environments for anomalous patterns or unauthenticated access to the functions of the Updates Environment Management component.

How to protect yourself

  • Identify all environments running Oracle PeopleSoft Enterprise PeopleTools in versions 8.61 or 8.62 [1].
  • Apply as soon as possible the patch or update that Oracle has released for this vulnerability; being listed in the KEV catalog, many organizations have tight regulatory deadlines for remediation [2].
  • Review PeopleSoft access logs for unauthorized activity or exploitation attempts, given confirmed active exploitation [2].
  • Restrict HTTP access to PeopleSoft environments from untrusted networks while you complete patching, since exploitation does not require authentication [1].
  • Prioritize this vulnerability over others of lower severity: with a CVSS of 9.8 and presence in KEV, the risk of full compromise is real and current [1][2].

Frequently asked questions

Do I need credentials for this vulnerability to be exploited against me? No. According to NVD, the attack does not require authentication or user interaction, only network access via HTTP [1].

Is this just a theoretical threat? No. The vulnerability is on CISA's KEV catalog, which only includes vulnerabilities with confirmed active exploitation [2].

Does it affect all versions of PeopleSoft? The available data specifically points to versions 8.61 and 8.62 of PeopleTools [1]; if you use another version, you should still check with Oracle whether it applies to you.

What if I can't patch immediately? Restrict network access to the affected environment and monitor logs while you plan the patching, given the risk of unauthenticated exploitation [1][2].

Sources

OCIRIA security team Threat monitoring & response · data from our real-time radar Live radar