CVE-2026-35273
Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 contain a critical flaw that lets anyone on the network take full control of the system via HTTP. The vulnerability can expose, alter, or delete data and disrupt services. It is highly exploitable and requires immediate attention.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Oracle PeopleSoft Enterprise PeopleTools 8.61 and 8.62, used by organizations running PeopleSoft applications.
Real-world impact
An attacker could gain complete control of the PeopleSoft environment, steal sensitive business data, modify or delete records, and bring the application down.
Why this severity
The CVSS score of 9.8 reflects that the flaw is network‑accessible, requires no user interaction or privileges, and can compromise confidentiality, integrity, and availability.
What to do about it
- 01Obtain and apply the Oracle PeopleSoft patch or configuration change for CVE-2026-35273 as detailed in the vendor’s security advisory.
- 02Restart the PeopleSoft services to complete the update.
CISA KEV required action
Timeline
- Jun 11, 2026 · Jun 11, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jun 12, 2026 · Jun 12, 2026Confirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- Jun 15, 2026 · Jun 15, 2026CISA remediation deadlineFederal agencies are required to remediate by this date.
- Jul 23, 2026 · 7d agoAdvisory updatedThe NVD record was last revised.
- Jul 23, 2026 · 7d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- oracle.com/security-alerts/alert-cve-2…vendor advisory
- cisa.gov/known-exploited-vulnerabili…third party advisoryus government resource