Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Splunk Enterprise Pre-Auth RCE Chain Exposes Database With Zero
June 13, 2026
Government Directive Blocks Anthropic Fable 5 & Mythos Access
June 13, 2026
Fancy Bear Abuses EdgeRouters & Cloud for Stealthy
June 12, 2026
Home/CyberSecurity News/Oracle Emergency Security Update to Fix Critical RCE Vulnerability
CyberSecurity News

Oracle Emergency Security Update to Fix Critical RCE Vulnerability

Oracle has released an emergency Security Alert, addressing a critical remote code execution vulnerability (CVE-2026-35273) within PeopleSoft Enterprise PeopleTools. The vulnerability carries a CVSS...

David kimber
David kimber
June 11, 2026 2 Min Read
10 0

Oracle has released an emergency Security Alert, addressing a critical remote code execution vulnerability (CVE-2026-35273) within PeopleSoft Enterprise PeopleTools.

The vulnerability carries a CVSS v3.1 score of 9.8, highlighting its severity and the urgent need for remediation across enterprise environments.

The flaw resides in the Updates Environment Management component of PeopleSoft PeopleTools and can be exploited remotely over HTTP.

It does not require authentication or user interaction, making it particularly dangerous for internet-facing systems.

Oracle confirmed that successful exploitation could allow attackers to execute arbitrary code, potentially leading to full system compromise.

Security researchers from TrendAI Zero Day Initiative, including Bobby Gould, Lucas Miller, and Minh Giang, were credited with discovering and reporting the vulnerability.

Their findings indicate that the attack complexity is low, which increases the likelihood of active exploitation attempts in the wild. The vulnerability impacts PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62.

Oracle Emergency Security Update

Oracle also warned that earlier or unsupported versions may be affected, even though they have not been formally tested.

Since patches are only released for supported versions under Premier or Extended Support, organizations running outdated systems face additional risk if they do not upgrade.

From a technical standpoint, the vulnerability allows network-based attacks without requiring any privileges.

It affects confidentiality, integrity, and availability at a high level, meaning attackers could access sensitive data, modify system configurations, or disrupt services entirely.

In a real-world scenario, a publicly exposed PeopleSoft instance could be compromised to deploy malicious payloads or facilitate lateral movement within a corporate network.

Oracle has released patches and mitigation guidance as part of the Security Alert and strongly recommends immediate action.

Organizations should prioritize applying the available updates, restrict external access to PeopleSoft environments, and monitor systems for suspicious activity.

Maintaining systems on supported versions is also critical to ensure continued access to security updates.

This issue underscores the ongoing threat posed by unauthenticated RCE vulnerabilities in widely deployed enterprise software.

Given PeopleSoft’s role in managing critical business operations such as HR and finance, exploitation of this flaw could have significant operational and data security consequences.

Organizations are advised to treat CVE-2026-35273 as a high-priority risk and take swift steps to secure their infrastructure.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityThreatVulnerability

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Ivanti Command Injection Vulnerability Exploited After PoC

Next Post

Cybercriminals Sell Stolen Credentials on Chinese Markets

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
OnyxC2 MaaS Hackers Steal Credentials Malware-as-a-Service From
June 12, 2026
Google Sues Chinese Cybercrime for Gemini AI Cyberattacks
June 12, 2026
Arch Linux AUR Supply Chain Attack Deploys Infostealers
June 12, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us