Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Levi Strauss Data Breach Exposes Customer and Employee Data
August 8, 2026
OpenAI Pauses Astra Model Development to Assess Cybersecurity Risks
August 8, 2026
Critical Linux Kernel SCTP Vulnerability Lets Attackers Gain Root
August 7, 2026
Home/CyberSecurity News/Oracle Patches Critical RCE Vulnerability CVE-2024-9999 in Fusion Middleware
CyberSecurity News

Oracle Patches Critical RCE Vulnerability CVE-2024-9999 in Fusion Middleware

Key Takeaways Oracle has issued an urgent security alert for a critical remote code execution (RCE) vulnerability, CVE-2026-35273. The flaw affects PeopleSoft Enterprise PeopleTools versions 8.61 and...

David kimber
David kimber
June 11, 2026 3 Min Read
50 0

Key Takeaways

  • Oracle has issued an urgent security alert for a critical remote code execution (RCE) vulnerability, CVE-2026-35273.
  • The flaw affects PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62, with a CVSS v3.1 score of 9.8.
  • It allows unauthenticated, remote attackers to execute arbitrary code without user interaction.
  • Patches are available, and immediate application is strongly recommended to prevent system compromise.

Critical RCE Flaw Discovered in Oracle PeopleSoft Enterprise PeopleTools

Oracle has released an emergency security alert addressing a severe remote code execution vulnerability, identified as CVE-2026-35273, within its PeopleSoft Enterprise PeopleTools platform. This critical flaw, which boasts a CVSS v3.1 score of 9.8, necessitates immediate attention from organizations utilizing PeopleSoft.

Table Of Content

  • Key Takeaways
  • Critical RCE Flaw Discovered in Oracle PeopleSoft Enterprise PeopleTools
  • Oracle’s Emergency Security Update and Recommendations
  • What You Should Do

The vulnerability specifically resides within the Updates Environment Management component of PeopleSoft PeopleTools. Exploitation can occur remotely over HTTP and, critically, does not require any authentication or user interaction. This makes the flaw exceptionally dangerous, particularly for internet-facing PeopleSoft deployments, as attackers could execute arbitrary code and potentially achieve full system compromise.

The discovery and reporting of CVE-2026-35273 are credited to security researchers Bobby Gould, Lucas Miller, and Minh Giang from the TrendAI Zero Day Initiative. Their analysis indicates that the vulnerability has low attack complexity, which significantly heightens the risk of active exploitation in real-world scenarios. The affected versions of PeopleSoft Enterprise PeopleTools include 8.61 and 8.62.

Oracle’s Emergency Security Update and Recommendations

While formal testing confirmed the vulnerability in PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62, Oracle has cautioned that earlier or unsupported versions may also be susceptible. Organizations operating outdated systems face elevated risk, as security patches are exclusively provided for versions under Premier or Extended Support. This underscores the critical importance of maintaining software on supported releases.

From a technical perspective, the vulnerability facilitates network-based attacks without requiring any prior privileges. Successful exploitation could severely impact confidentiality, integrity, and availability, allowing attackers to access sensitive data, alter system configurations, or completely disrupt critical services. In a practical attack scenario, a publicly exposed PeopleSoft instance could be compromised to deploy malicious payloads or serve as a foothold for lateral movement within a corporate network.

Oracle has made patches and mitigation guidance available as part of its Security Alert. The company strongly urges immediate action to apply these updates, restrict external access to PeopleSoft environments, and diligently monitor systems for any indicators of suspicious activity. Ensuring systems remain on supported versions is paramount for continuous access to vital security updates.

This incident highlights the persistent threat posed by unauthenticated remote code execution vulnerabilities in widely deployed enterprise software. Given PeopleSoft’s integral role in managing critical business functions like HR and finance, the exploitation of this flaw could lead to severe operational disruptions and significant data security breaches. Organizations are advised to prioritize CVE-2026-35273 as a high-priority risk and implement swift measures to secure their infrastructure.

What You Should Do

  • Immediately apply the patches and mitigation guidance provided in Oracle’s Security Alert for CVE-2026-35273.
  • Restrict external network access to PeopleSoft environments as much as possible, implementing strict firewall rules and access controls.
  • Monitor PeopleSoft systems and associated network traffic for any signs of suspicious activity or attempted exploitation.
  • Ensure all PeopleSoft Enterprise PeopleTools instances are running supported versions (8.61 or 8.62 with patches, or later supported versions) to guarantee access to future security updates.
  • Conduct regular security audits and penetration testing of PeopleSoft deployments to identify and address potential vulnerabilities proactively.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityThreatVulnerability

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Critical Ivanti Sentry RCE Vulnerability CVE-2023-46807 Exploited in Attacks

Next Post

Chinese-Language Guarantee Marketplaces Trade Stolen Credentials

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Zapscape KVM Vulnerability CVE-2026-64561 Allows Guest-to-Host Escape
August 7, 2026
Chrome 101 Patches 41 Vulnerabilities, 6 Critical Memory Bugs
August 7, 2026
Patchwork APT Uses Fake PDFs, Chat Apps to Spy on PCs, Android
August 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us