CVE Tools
Back to feed
Rapid7 Blog ·EN Vendor research

Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)

By Jonah Burgess··4 min read

Overview

On June 10, 2026, Oracle published a security alert for CVE-2026-35273">CVE-2026-35273, a critical vulnerability in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools. Oracle released an out-of-band patch the same day as the advisory, underscoring the urgency of remediation. The vulnerability has a CVSSv3.1 score of 9.8 and is remotely exploitable without authentication. Per the vendor advisory, successful exploitation may result in remote code execution (RCE). TrendAI has classified the underlying flaw as a server-side request forgery (CWE-918). PeopleTools versions 8.61 and 8.62 are affected.…

Continue reading on Rapid7 Blog