CISA Warns of Critical Oracle PeopleSoft 0-Day Actively Exploited
Key Takeaways CISA has identified a critical zero-day vulnerability, CVE-2026-35273, in Oracle PeopleSoft Enterprise PeopleTools. The flaw allows unauthenticated remote attackers to gain full control...
Key Takeaways
- CISA has identified a critical zero-day vulnerability, CVE-2026-35273, in Oracle PeopleSoft Enterprise PeopleTools.
- The flaw allows unauthenticated remote attackers to gain full control over affected systems, bypassing authentication mechanisms.
- This vulnerability is actively being exploited in the wild, including in ransomware campaigns.
- Immediate patching and mitigation are required, with a CISA remediation deadline of June 15, 2026.
CISA Issues Urgent Alert for Actively Exploited Oracle PeopleSoft 0-Day
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a severe warning regarding a zero-day vulnerability in Oracle PeopleSoft, officially designated as CVE-2026-35273. This critical flaw has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, confirming its active exploitation by malicious actors.
Table Of Content
The vulnerability impacts Oracle PeopleSoft Enterprise PeopleTools and poses a significant risk as it allows unauthenticated attackers to achieve complete system compromise. Classified under CWE-306 (Missing Authentication for Critical Function), the flaw bypasses essential authentication protocols, enabling unauthorized access to sensitive operations.
The Threat Landscape of CVE-2026-35273
According to CISA, threat actors are leveraging CVE-2026-35273 in ongoing ransomware campaigns, raising alarms for organizations heavily reliant on PeopleSoft environments. While specific technical details of the exploits remain undisclosed, the nature of the vulnerability suggests attackers can remotely access administrative functions exposed to the internet without needing valid credentials.
Oracle PeopleSoft Enterprise PeopleTools is a cornerstone for many enterprise resource planning (ERP) applications globally. This makes it a prime target for adversaries seeking access to high-value assets. Successful exploitation could lead to unauthorized access to critical financial, human resources, and operational data, facilitate the deployment of ransomware payloads, and establish persistent footholds within corporate networks.
CISA’s Directive and Remediation Timeline
CISA formally added CVE-2026-35273 to its KEV catalog on June 12, 2026. In accordance with Binding Operational Directive (BOD) 26-04, federal agencies and other organizations are mandated to remediate this vulnerability by June 15, 2026. This directive underscores the urgency of addressing actively exploited flaws that pose immediate and severe risks.
The agency strongly advises organizations to promptly apply all vendor-provided patches and mitigations. In scenarios where patches are not yet available, CISA recommends either discontinuing the use of affected systems or implementing robust compensating controls to minimize exposure. Security teams must also conduct thorough assessments of internet-facing assets to identify any vulnerable PeopleSoft instances and immediately restrict unauthorized access.
What You Should Do
- Apply Patches Immediately: Prioritize and install any available patches or security updates from Oracle for PeopleSoft Enterprise PeopleTools.
- Implement Compensating Controls: If patches are not yet available, implement strict network segmentation, restrict access to PeopleSoft instances from the internet, and consider discontinuing use of affected systems temporarily.
- Monitor for Exploitation: Conduct thorough log analysis and network monitoring for indicators of compromise, including unusual administrative activity, unauthorized access attempts, and unexpected system changes. Refer to CISA’s “Forensics Triage Requirements.”
- Review Backup and Recovery Plans: Ensure data integrity and verify the effectiveness of backup strategies to mitigate potential ransomware impacts.
- Enhance Access Controls: While not a full mitigation for this authentication bypass flaw, reinforce multi-factor authentication (MFA) and granular access controls across your environment to reduce overall attack surface.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.