Oracle Security Update – 12 June 2026

Oracle has released a security update to fix a critical zero-day vulnerability affecting Oracle PeopleSoft Enterprise PeopleTools.

The addressed vulnerability could allow the unauthenticated attacker with network access via HTTP to execute arbitrary code, leading to the compromise and a complete takeover of the affected systems.

The addressed vulnerability:

Oracle PeopleSoft Enterprise PeopleTools Remote Code Execution Vulnerability (CVE-2026-35273):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Remote Code Execution

It should be highlighted that Oracle is aware that the zero-day vulnerability “CVE- 2026-35273” is being exploited in the wild.

Vulnerabilities

CVE-2026-35273

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Oracle Security Advisory

References