← Back to Vulnerability Reports CVE Intelligence

CVE-2026-35273

Oracle PeopleSoft SuiteCRITICAL · CVSS 9.8No exploitation reported

What is CVE-2026-35273?

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS9.8 NVD 3.1
SeverityCRITICAL
ExploitationNo exploitation reported
EPSS<1% · P7
Triage statusNo Known Exploit
ActionPatch within 48 hours
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWECWE-306
NVD published2026-06-11
NVD last modified2026-06-11

Affected product

Oracle PeopleSoft Suite

Remediation Steps

  1. Apply the critical security patch released by Oracle immediately
  2. Verify all PeopleSoft systems are updated before re-enabling internet exposure
  3. Monitor access logs for indicators of prior compromise during the May 27 – June 10 exploitation window
  4. Review telemetry and data access logs for unauthorized activity
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.

Get Critical CVE Alerts

Subscribe free and hear about actively exploited CVEs like this one first.