CVE-2026-35273

Published Jun 11, 2026

Last updated a month ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-35273 is a remote code execution (RCE) vulnerability affecting Oracle PeopleSoft Enterprise PeopleTools, specifically within the Updates Environment Management component, also known as the Environment Management Hub (PSEMHUB). This flaw allows an unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools without requiring user interaction. Successful exploitation can lead to a complete takeover of the affected system. The vulnerability impacts PeopleTools versions 8.61 and 8.62, with earlier unsupported versions also likely susceptible. It was actively exploited as a zero-day by the ShinyHunters extortion crew (tracked as UNC6240 by Mandiant) between May 27 and June 9, 2026, prior to Oracle's advisory on June 10. The attacks primarily targeted universities and leveraged missing authentication checks in PSEMHUB HTTP endpoints to execute arbitrary code through crafted POST requests to `/PSEMHUB/hub` or `/PSIGW/HttpListeningConnector`.

Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Source
secalert_us@oracle.com
NVD status
Analyzed
Products
peoplesoft_enterprise_peopletools

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
Exploit added on
Jun 12, 2026
Exploit action due
Jun 15, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-306

Social media

Hype score
Not currently trending
  1. 22:19 UTC: CVE-2026-35273 disclosed. CVE-2026-35273 - Oracle PeopleSoft Environment Management Hub Exploitation Kit Overview CVE-2026-35273 is a critica

    @lyrie_ai

    13 Jul 2026

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. CVE-2026-35273: CVE-2026-35273 - Oracle PeopleSoft: Unauthenticated Takeover of Updates Environment Management Exploit kit in making... Will add it to #0days #0dayz #exploit #CVE #CVSS #RCE

    @lyrie_ai

    12 Jul 2026

    66 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. CVE-2026-35273. 0day Intel: CVE-2026-35273 - Oracle PeopleSoft: Unauthenticated Takeover of Updates Environm

    @lyrie_ai

    12 Jul 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. CVE-2026-35273: The entry point to a full RCE chain. It’s not just another SSRF. The real story behind the CVE-2026-35273 chaos: Critical Alert: CVE-2026-35273 (CVSS 9.8) Unauthenticated RCE via SSRF in Oracle PeopleSoft PeopleTools 8.61 & 8.62. If you run PeopleTools

    @lyrie_ai

    11 Jul 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. 13:49 UTC: CVE-2026-35273 disclosed. 🚨 On 6/10/26, #Oracle published a security alert for CVE-2026-35273, a critical vuln. affecting PeopleSoft Enterprise P

    @lyrie_ai

    9 Jul 2026

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. CVE-2026-35273: 🛡️ We added Oracle PeopleSoft Enterprise PeopleTools missing authentication for critical function vulnerability CVE-2026-35273 to our KEV Catalog. Visit & apply mitigations to protect your org from cyberattacks. #Cybersecurity…

    @lyrie_ai

    8 Jul 2026

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  7. CVE-2026-35273. 0day Intel: 🚨 A critical Oracle PeopleSoft zero day tracked as CVE-2026-35273 (CVSS 9.8) al

    @lyrie_ai

    8 Jul 2026

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  8. CVE-2026-35273: ‼️ Critical Oracle PeopleSoft PeopleTools RCE Exposes Enterprise Systems (CVE-2026-35273) 0day Intel: ‼️ Critical Oracle PeopleSoft PeopleTools RCE Exposes Enterprise Systems (CVE-20

    @lyrie_ai

    7 Jul 2026

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  9. CVSS 9.8, no auth, just HTTP. ShinyHunters dropped README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT into 100+ PeopleSoft servers before Oracle had an advisory. Patch CVE-2026-35273. Yesterday. 💀 #Oracle #PeopleSoft #CVE https://t.co/vEBtmNd0Gx

    @FpeSre

    21 Jun 2026

    70 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. ⚠️ ثغرة صفرية حرجة في أوراكل بيبل سوفت مستغلة فعلياً تتيح تنفيذ أوامر عن بعد دون مصادقة المعرّف : CVE-2026-35273 المنتج المتأثر : Oracle PeopleSoft Suite الحل : Apply Oracle emerge

    @KasperskyDev

    20 Jun 2026

    86 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 🚨 A new ransomware-linked vulnerability has recently been added to DarkFeed's CISA KEV monitoring. CVE-2026-35273 affects Oracle PeopleSoft Enterprise PeopleTools and allows unauthenticated attackers to potentially gain control over vulnerable systems. The vulnerability is h

    @ido_cohen2

    20 Jun 2026

    2979 Impressions

    8 Retweets

    27 Likes

    18 Bookmarks

    2 Replies

    0 Quotes

  12. # CVE-2026-35273 - Oracle PeopleSoft Environment Management Hub Exploitation Kit # Overview CVE-2026-35273 is a critical, unauthenticated remote code execution vulnerability in the **Updates Environment Management** component of Oracle PeopleSoft Enterprise PeopleTools. The flaw

    @YogSoth0

    18 Jun 2026

    509 Impressions

    1 Retweet

    8 Likes

    0 Bookmarks

    2 Replies

    0 Quotes

  13. CVE-2026-35273: Kritische PeopleSoft-Lücke (CVSS 9.8) wird aktiv ausgenutzt. Über 100 Organisationen betroffen, vor allem im Hochschulbereich. Oracle hat Mitigations veröffentlicht. ⚠️ #CVE #CyberSecurity #PatchNow https://t.co/CcM6cGYhER

    @wall_your_x

    18 Jun 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Alert: Active Exploitation of Oracle PeopleTools (CVE-2026-35273) https://t.co/yorYsPx6Ya

    @Rw_csirt

    17 Jun 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. CVE-2026-35273: Oracle PeopleSoftのゼロデイ脆弱性の悪用 CVE-2026-35273: Active Exploitation of Oracle PeopleSoft Zero-Day Vulnerability #SecurityBoulevard (Jun 16) https://t.co/z73xJVTIO8

    @foxbook

    17 Jun 2026

    267 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Top #CVE to patch 👀 * #Ivanti Sentry unauth #RCE (CVE-2026-10520 * #CheckPoint VPN auth bypass (CVE-2026-50751) * @Oracle PeopleSoft missing auth (CVE-2026-35273) * @Microsoft Exchange Server (CVE-2026-42897) * @Microsoft June #PatchTuesday — 200+ CVEs, 38 critical. * @Goog

    @stansecure

    17 Jun 2026

    120 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  17. CVE-2026-35273: Oracle PeopleSoft Zero-Day RCE Actively Exploited CVSS 9.8 zero-day CVE-2026-35273 hit 300+ Oracle PeopleSoft instances before the… Read more: https://t.co/mmSpfVhSro #Oracle #Peoplesoft #ZeroDay #RemoteCodeExecution

    @navanem

    16 Jun 2026

    0 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. استغلت مجموعة ShinyHunters ثغرة يوم الصفر CVE-2026-35273 في Oracle PeopleSoft لاختراق جامعات ومؤسسات تعليمية وسرقة البيانات، قبل إصدار Oracle للتحذير الأمني والتحديثات اللازمة

    @fad_777

    16 Jun 2026

    81 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. 🚨 Oracle PeopleSoft Zero-Day CVE-2026-35273 was exploited by ShinyHunters to breach universities. Critical RCE risk. Patch now, restrict PSEMHUB/PSIGW, and check logs. https://t.co/HnjQzEMVla #CyberSecurity #Oracle #ZeroDay #CVE #Vulert

    @vulert_official

    15 Jun 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. Oracle PeopleSoft CVE-2026-35273 added to CISA KEV. Missing authentication for critical function. CVSS 9.8. Mandiant confirmed exploitation in the wild. Enterprise ERP systems are the new crown jewels. Act accordingly.

    @hieyz6838

    15 Jun 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. June 2026 Patch Tuesday buried a 9.8 CVSS RCE bug in Oracle PeopleTools (CVE-2026-35273). If your patching process didn’t flag this in 24 hours, your “readiness” is a checklist, not a capability. The ribbon-cutting is not the accomplishment.

    @jlabernathy

    14 Jun 2026

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  22. CVE-2026-35273 in Oracle PeopleSoft PeopleTools EMHub Under Active Exploitation https://t.co/ECGahbqYQt CVE-2026-35273 in Oracle PeopleSoft PeopleTools EMHub Under Active Exploitation Oracle has disclosed CVE-2026-35273, a critical Remote Code Execution (RCE) zero-day vulnera

    @f1tym1

    14 Jun 2026

    116 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. CVE-2026-35273 (CVSS 9.8) in Oracle PeopleSoft EMHub actively exploited by ShinyHunters since late May. Unauthenticated RCE affects PeopleTools 8.61/8.62. Block /PSEMHUB/* and /PSIGW/HttpListeningConnector paths immediately. #DFIR_Radar https://t.co/EzfU0nCYOu

    @DFIR_Radar

    14 Jun 2026

    181 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  24. CVE-2026-35273 - Oracle PeopleSoft: Unauthenticated Takeover of Updates Environment Management Exploit kit in making... Will add it to https://t.co/K2BXNRWUsR #0days #0dayz #exploit #CVE #CVSS #RCE https://t.co/xL5PcF1bQX

    @YogSoth0

    13 Jun 2026

    514 Impressions

    3 Retweets

    9 Likes

    1 Bookmark

    5 Replies

    0 Quotes

  25. 🚨 CVE-2026-35273: Oracle PeopleSoft Enterprise PeopleTools has an unauthenticated remote code execution bug. CVSS 9.8. CISA added it to the KEV catalog on June 12, 2026 with known ransomware campaign use, so it is being exploited now. #KEV #CVE https://t.co/iSCReRV6dc

    @cloudkey_tech

    13 Jun 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  26. DFIR Weekly Recap | Oracle PeopleSoft zero-days and device code phishing dominated this week's threat landscape. • Oracle PeopleSoft CVE-2026-35273 seeing active exploitation with ShinyHunters targeting education sector • Device code phishing bypassing traditional password h

    @DFIR_Radar

    13 Jun 2026

    165 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  27. #threatreport #MediumCompleteness Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273) | 12-06-2026 Source: https://t.co/xvc4YAcX7K Key details below ↓ 🧑‍💻Actors/Campaigns: Unc6240 (🧠motivation: cyber_criminal, information_theft) Shinyhunters (🧠moti

    @rst_cloud

    13 Jun 2026

    92 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. 🚨 CRITICAL: CVE-2026-35273 in Oracle PeopleSoft PeopleTools allows unauthenticated takeover. CISA KEV listed, ransomware exploitation known. Patch immediately. #CVE #PatchNow #ThreatIntel https://t.co/7w6jkvxtfv

    @DFIR_Lab

    13 Jun 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. Cyber Heat Radar|2026/06/13 05:00 JST 今回は①CVE-2026-35273 CISA KEV追加の件、②Check Point VPN CVE-2026-50751…の件、③Ivanti脆弱性 連邦機関にパッチ命令の件を中心に、ほか3件を含めて音声で6件扱います。

    @cyberheatradar

    12 Jun 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. Threat Intel Brief — 2026-06-12 Today’s real signal is ShinyHunters/UNC6240 turning Oracle PeopleSoft into an extortion lane, not a generic “new CVE” story. GTIG/Mandiant says the group exploited CVE-2026-35273 as a zero-day against Oracle PeopleSoft Environment Managem

    @alphahunt_io

    12 Jun 2026

    155 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  31. ShinyHunters used an Oracle PeopleSoft zero-day to breach universities. CVE-2026-35273 scores 9.8. Patch guidance and IOCs inside. https://t.co/kk81XBdr7T #ShinyHunters #OraclePeopleSoft #CVE #ZeroDay #PSEMHUB #UniversityDataBreach #RCE #Mandiant #PeopleTools #ExtortionGroup ht

    @redsecuretech

    12 Jun 2026

    79 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  32. 🚨 Two critical zero-days in Ivanti Sentry and Oracle PeopleSoft are under active exploitation right now. Plus, a new BitLocker bypass (GreatXML) is public. What happened: Ivanti Sentry (CVE-2026-10520) and Oracle PeopleSoft (CVE-2026-35273) flaws are being actively exploited

    @gh0st_V3ctbrv

    12 Jun 2026

    87 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. 💭 ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities Data Breach / Critical CVE: The ShinyHunters extortion crew ex... https://t.co/MQJd6TsmsC #DataBreach #CVE #ZeroDay #DataProtection

    @MyDooM15

    11 Jun 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. Oracle's PeopleSoft stack is reading like an open book — and ShinyHunters is doing the reading. CVE-2026-35273, unauthenticated remote code execution in PeopleTools 8.61 and 8.62, landed in an emergency out-of-band advisory today. No credentials required. No full patch released

    @GoCocoaAI

    11 Jun 2026

    140 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  35. 🚨 CVE-2026-35273 — CVSS 9.8/10 ██████████ Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/lB9e4CKyJO

    @OrizonCyber

    11 Jun 2026

    165 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

Configurations