run Oracle PeopleSoft? the bug that breached 100+ orgs was exploited two weeks before the fix existed

CVE-2026-35273 is a 9.8 pre-auth RCE ShinyHunters used as a zero-day on universities before Oracle had a patch. It's fixed in the July CPU — here's…

Aliteq
Priya Nair · Software & Systems Editor

What you need to know

Affected: Oracle PeopleSoft Enterprise PeopleTools 8.61 and 8.62 (per Oracle's alert and Tenable's advisory).

What you need to know

The flaw: an SSRF in the Updates Environment Management component, chained with CVE-2026-35278, yields unauthenticated remote code execution over HTTP.

What you need to know

Exploited since: May 27, 2026 — two weeks before the vendor advisory. This was a genuine zero-day, so assume compromise is possible even on recently-patched systems.

What you need to know

Fix: the July 2026 Critical Patch Update (the June out-of-band patch also covers it). No viable workaround fully substitutes for patching.

What you need to know

Exposed endpoints: /PSEMHUB/hub and /PSIGW/HttpListeningConnector — block external access to these at the firewall today.

The one-line version

PeopleTools 8.61 and 8.62 are affected. This is a pre-auth RCE chain (CVSS 9.8) that's already in CISA's Known Exploited Vulnerabilities catalog and confirmed used in the wild. Apply the July CPU…

Aliteq

Read the full story

run Oracle PeopleSoft? the bug that breached 100+ orgs was exploited two weeks before the fix existed

Read the full story on Aliteq