All CVEs
Vulnerability intelligence

CVE-2026-35273

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS Score
9.8
Critical
EPSS — Exploit Probability
94%
Riskier than 100% of all CVEs
Exploitation
Confirmed in the wild
KEV since 2026-06-12
Remediation
Patch available
Federal deadline 2026-06-15
NVD entry Vendor patch PoC / advisory CISA KEV

18 articles across 11 outlets · first covered Jun 11, 2026 · latest Jun 30, 2026

Tracked incidents

Associated threat actors

Coverage timeline