Back Csa.Sg Critical Vulnerability in Oracle PeopleSoft Enterprise PeopleTools
Oracle has released security updates to address a critical vulnerability in Oracle PeopleSoft Enterprise PeopleTools that could allow unauthenticated attackers to perform remote code execution and fully compromise the affected system. Patch immediately.
Oracle has released security updates to address a critical vulnerability (CVE-2026-35273) affecting the Updates Environment Management component of Oracle PeopleSoft Enterprise PeopleTools. The vulnerability has a Common Vulnerability Scoring System (CVSS v3.1) score of 9.8 out of 10.
Due to missing authentication for a critical function in Oracle PeopleSoft Enterprise PeopleTools Updates Environment Management, an unauthenticated attacker with network access via HTTP could send specially crafted requests to achieve remote code execution (RCE), potentially leading to full system compromise.
This vulnerability is reportedly being actively exploited in the wild.
The vulnerability affects Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62.
Users and administrators of affected products are advised to update the affected products to the latest version immediately.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
