#PeopleTools
📌 CVE-2026-83019 - Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8... https://www.cyberhub.blog/cves/CVE-2026-83019
CVE-2026-83019
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Su
www.cyberhub.blog
September 25, 2026 at 8:07 PM
📌 CVE-2026-83014 - Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager). Supported versions that are affected a... https://www.cyberhub.blog/cves/CVE-2026-83014
CVE-2026-83014
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleT
www.cyberhub.blog
September 25, 2026 at 7:37 PM
PeopleTools 8.62 + WebLogic Remote Console: The Middleware Upgrade You Didn't Know You Needed: https://aaronengelsrud.com/2025/07/13/peopletools-weblogic-remote-console-the.html

PeopleTools 8.62 introduces official support for the WebLogic Remote Console, enhancing security, performance, and usa...
July 13, 2025 at 10:28 PM
Upgrading #PeopleTools before moving to SaaS isn't “nice to have."
It's strategic.

My latest post breaks down the 5 biggest reasons to upgrade now, including modern APIs, cloud-readiness, and the elimination of migration roadblocks.

👉 open.substack.com/pub/peoples...

#PeopleSoft #ERP #SaaS
December 18, 2025 at 3:14 PM
📌 CVE-2026-83017 - Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Report Distribution). Supported versions that are aff... https://www.cyberhub.blog/cves/CVE-2026-83017
CVE-2026-83017
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Report Distribution). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise
www.cyberhub.blog
September 22, 2026 at 8:37 PM
U.S. CISA adds Oracle PeopleSoft Enterprise PeopleTools flaw to its Known Exploited Vulnerabilities catalog
U.S. CISA adds Oracle PeopleSoft Enterprise PeopleTools flaw to its Known Exploited Vulnerabilities catalog
U.S. CISA adds Oracle PeopleSoft Enterprise PeopleTools flaw to its Known Exploited Vulnerabilities catalog.
securityaffairs.com
June 13, 2026 at 9:38 AM
🎉 Join us in welcoming Matheshwaran Viswanathan as a new #OracleACE Associate! 🇮🇳

With expertise in PeopleSoft PeopleTools and a passion for bringing AI/ML-driven innovation to the community, Matheshwaran is dedicated to sharing insights and helping the community.

ace.oracle.com/ords/ace/pro... 🚀
February 6, 2026 at 10:30 AM
PeopleTools 8.54: Performance Performance Monitor Enhancements: This is part of a series of articles about new...
November 22, 2024 at 1:30 PM
🛑 CVE-2026-35273
Oracle PeopleSoft Enterprise PeopleTools
CVSS 9.8 / EPSS 0% / KEV ✅
TL;DR: Vulnerability in the PeopleSoft Enterprise PeopleTools product of O…
https://cvesentinel.com/report/CVE-2026-35273?utm_source=bluesky&utm_medium=social&utm_campaign=cvesentinel
#infosec #CVE #vulnerability
June 12, 2026 at 5:49 PM
Built a sample framework in PeopleSoft to return data which takes into account the environment that you are running in...

practicalpeoplesoft.blogspot.com/2026/01/envi...

#peoplesoft #peopletools
Environment Specific Variables
This is something I've been meaning to address for a while now. Quite a simple problem. The issue around having PeopleSoft pick the right va...
practicalpeoplesoft.blogspot.com
January 30, 2026 at 8:01 PM
🚨 On 6/10/26, #Oracle published a security alert for CVE-2026-35273, a critical vuln. affecting PeopleSoft Enterprise PeopleTools.

The campaign has been attributed to the ShinyHunters collective, well known for data theft and extortion. More in our blog: r-7.co/4aEClz9
June 12, 2026 at 1:48 PM
Oracle PeopleSoft PeopleTools Critical CVE 98: Unauthenticated HTTP Exploit Threatens Full Enterprise Takeover

Introduction: Silent Enterprise Risk Hidden Inside Oracle PeopleSoft Infrastructure A newly disclosed critical vulnerability in Oracle’s PeopleSoft Enterprise PeopleTools has raised…
Oracle PeopleSoft PeopleTools Critical CVE 98: Unauthenticated HTTP Exploit Threatens Full Enterprise Takeover
Introduction: Silent Enterprise Risk Hidden Inside Oracle PeopleSoft Infrastructure A newly disclosed critical vulnerability in Oracle’s PeopleSoft Enterprise PeopleTools has raised serious concern across enterprise IT environments worldwide. Affecting versions 8.61 and 8.62, this flaw sits inside the Updates Environment Management component and enables unauthenticated attackers to compromise systems remotely through HTTP access. What makes this vulnerability especially dangerous is its simplicity of exploitation combined with its severity.
undercodenews.com
June 12, 2026 at 5:49 PM
⚠️ Oracle PeopleSoft PeopleTools 8.61 & 8.62 face a CRITICAL remote vuln (CVSS 9.8). Unauthenticated attackers can take over systems. Patch or upgrade now! https://radar.offseq.com/threat/cve-2026-35273-vulnerability-in-the-peoplesoft-ent-9ad1390c #OffSeq #Oracle #PatchNow
CVE-2026-35273: Vulnerability in the PeopleSoft Enterprise PeopleTools product o
This vulnerability in Oracle PeopleSoft Enterprise PeopleTools (versions 8.61 and 8.62) allows an unauthenticated attacker with network access via HTTP to remotely execute code and fully compromise the affected system. The flaw resides in t
radar.offseq.com
June 11, 2026 at 4:30 AM
📌 CVE-2026-35288 - Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package). Supported versions that are a... https://www.cyberhub.blog/cves/CVE-2026-35288
CVE-2026-35288
Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where PeopleSoft Enterpr
www.cyberhub.blog
July 20, 2026 at 10:37 AM
📌 CVE-2026-35273 - Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions th... https://www.cyberhub.blog/cves/CVE-2026-35273
CVE-2026-35273
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleS
www.cyberhub.blog
June 12, 2026 at 8:07 PM
🚨 PeopleTools 8.62 now supports the WebLogic Remote Console 🚨

✅ Secure
✅ REST-based
✅ Cloud-ready

It’s the modern tool PeopleSoft admins didn’t know they needed.

👇 Full breakdown:
aaronengelsrud.com/2025/07/13/...

#PeopleSoft #PeopleTools862 #Oracle #WebLogic
July 14, 2025 at 2:17 PM
Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8) — zero-day sfruttato da ShinyHunters per 14 giorni, 100+ org colpite prima del patch out-of-band del 10/06. Unauthenticated RCE. Aggiornare PeopleTools 8.61/8.62. #ThreatIntel
June 12, 2026 at 10:57 PM
Oracle rates it CVSS 9.8: unauthenticated HTTP RCE in PeopleTools 8.61/8.62. EPSS is still very low and KEV may lag. That’s the lesson: once credible exploitation is reported, don’t let scoring models outrank the incident reality.
June 12, 2026 at 12:50 PM
Oracle issued an out-of-band fix for CVE-2026-35273, a critical PeopleSoft flaw that may allow unauthenticated remote code execution in PeopleTools 8.61 and 8.62. #Oracle #PeopleSoft #Nottingham
Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks
Oracle issued an out-of-band advisory for CVE-2026-35273, a critical PeopleSoft vulnerability that could allow unauthenticated remote code execution in PeopleSoft Enterprise PeopleTools 8.61 and 8.62. Reports also link the issue to ShinyHunters activity targeting hundreds of PeopleSoft instances across more than 100 organizations, with organizations such as the University of Nottingham...
www.hendryadrian.com
June 12, 2026 at 5:45 AM
Oracle Emergency Security Update to Fix Critical RCE Vulnerability
Oracle Emergency Security Update to Fix Critical RCE Vulnerability
Oracle has issued an emergency Security Alert to address a critical remote code execution vulnerability (CVE-2026-35273) affecting PeopleSoft Enterprise PeopleTools. The vulnerability carries a CVSS v3.1 score of 9.8, highlighting its severity and the urgent need for remediation across enterprise environments. The flaw resides in the Updates Environment Management component of PeopleSoft PeopleTools and can be exploited remotely over HTTP. It does not require authentication or user interaction, making it particularly dangerous for internet-facing systems. Oracle confirmed that successful exploitation could allow attackers to execute arbitrary code, potentially leading to full system compromise. Security researchers from TrendAI Zero Day Initiative, including Bobby Gould, Lucas Miller, and Minh Giang, were credited with discovering and reporting the vulnerability. Their findings indicate that the attack complexity is low, which increases the likelihood of active exploitation attempts in the wild. The vulnerability impacts PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62. Oracle Emergency Security Update Oracle also warned that earlier or unsupported versions may be affected, even though they have not been formally tested. Since patches are only released for supported versions under Premier or Extended Support, organizations running outdated systems face additional risk if they do not upgrade. From a technical standpoint, the vulnerability allows network-based attacks without requiring any privileges. It affects confidentiality, integrity, and availability at a high level, meaning attackers could access sensitive data, modify system configurations, or disrupt services entirely. In a real-world scenario, a publicly exposed PeopleSoft instance could be compromised to deploy malicious payloads or facilitate lateral movement within a corporate network. Oracle has released patches and mitigation guidance as part of the Security Alert and strongly recommends immediate action. Organizations should prioritize applying the available updates, restrict external access to PeopleSoft environments, and monitor systems for suspicious activity. Maintaining systems on supported versions is also critical to ensure continued access to security updates. This issue underscores the ongoing threat posed by unauthenticated RCE vulnerabilities in widely deployed enterprise software. Given PeopleSoft’s role in managing critical business operations such as HR and finance, exploitation of this flaw could have significant operational and data security consequences. Organizations are advised to treat CVE-2026-35273 as a high-priority risk and take swift steps to secure their infrastructure. Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates. The post Oracle Emergency Security Update to Fix Critical RCE Vulnerability appeared first on Cyber Security News .
cybersecuritynews.com
June 11, 2026 at 12:28 PM
TSUITE Playbook: Perimeter under active exploit. CVE-2026-10520 & CVE-2026-35273 bypass authentication. Hunt access logs for POSTs to /handleMessage & /PSEMHUB. ShinyHunters is dropping MeshCentral backdoors. Run emergency updates to Sentry 10.7.1+ & PeopleTools now. https://thecybermind.co/v6i6
TSUITE — Unified Perimeter Threat Mitigation Playbook For CVE-2026-35373 and CVE-2026-10520 | TheCyberMind.co™
A deep-dive engineering playbook for detecting and neutralizing synchronized perimeter exploits hitting Ivanti Sentry and Oracle PeopleSoft. Establish structural middleware surveillance and block active C2 propagation.
thecybermind.co
June 13, 2026 at 8:07 PM
Ask Who Has PeopleTools Security. Then Run the Query.

You'll get a name and a shrug: three or four people, maybe five. The join across role, permission list and user profile usually says eleven, and two of them left in 2023.
August 27, 2026 at 7:27 PM
The Component You Forgot Is the One They Use

August brought a 9.8 in PeopleTools plumbing most sites forgot was still enabled. Same pattern as June. The dangerous surface isn't what you built—it's what you never turned off.
August 26, 2026 at 7:29 PM
A Test Environment That Drifts Is a Test You Can't Trust

Different PeopleTools patch level, different customizations, data from two refreshes ago. Every difference between test and production is a false result waiting to surface on a Saturday night.
August 24, 2026 at 7:33 PM