www.cisa.gov 6/12/2026, 9:44:30 PM · external

CISA Adds Oracle PeopleSoft Flaw CVE-2026-35273 to KEV Catalog

Developing story vulnerability 14 articles tracked
Oracle PeopleSoft zero‑day (CVE-2026-35273) exploited by ShinyHunters
CyberSIXT Evidence Panel
Primary Source oracle.com
CISA KEV Listed in KEV
Patch Patch Available

THE Known Exploited Vulnerabilities (KEV) Catalog, maintained by CISA, serves as an authoritative resource for vulnerabilities actively exploited in the wild, helping organizations manage risks and prioritize vulnerability management. A specific entry highlights CVE-2026-35273 affecting Oracle PeopleSoft Enterprise PeopleTools, which has a missing authentication vulnerability allowing unauthenticated exploitation.

Organizations are advised to implement mitigations per vendor guidance and follow CISA's direction on prioritizing security updates based on risk. Users can nominate new vulnerabilities for inclusion in the catalog and subscribe for updates.

View Primary Source Via www.cisa.gov

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline