Oracle has issued an out of band security alert for CVE-2026-35273, a zero day vulnerability affecting Oracle PeopleSoft PeopleTools that is reportedly being exploited in the wild.
The flaw is remotely exploitable without authentication and may allow remote code execution, creating significant risk for organizations running exposed PeopleSoft infrastructure. Reported activity has targeted PeopleSoft application components, including Environment Management Hub endpoints, with threat actors allegedly using old and zero day vulnerabilities to access systems, extract credentials, map connected nodes, and steal data.
Organizations using PeopleSoft should immediately review affected versions, validate exposure of PSEMHUB and PSIGW endpoints, apply available Oracle guidance, disable or remove Environment Management Hub where possible, block external access to vulnerable paths, and review logs for indicators of compromise.
PeopleSoft environments often support sensitive HR, student, financial, and business records, which makes rapid response critical.
#Cybersecurity #Oracle #PeopleSoft #CVE202635273 #ZeroDay #VulnerabilityManagement #ThreatIntelligence #RemoteCodeExecution #PatchManagement #DataSecurity