{"id":17926,"date":"2026-06-18T14:00:00","date_gmt":"2026-06-18T14:00:00","guid":{"rendered":"https:\/\/www.securitytoday.de\/?p=17926"},"modified":"2026-06-19T09:58:28","modified_gmt":"2026-06-19T09:58:28","slug":"oracle-peoplesoft-actively-exploited-vulnerability-cisa-warns","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/06\/18\/oracle-peoplesoft-actively-exploited-vulnerability-cisa-warns\/","title":{"rendered":"Oracle PeopleSoft: actively exploited vulnerability, CISA warns"},"content":{"rendered":"<p style=\"color:#69d8ed;font-size:0.9em;margin:0 0 16px;padding:0;\">6 min read<\/p>\n<p><strong>A critical gap in Oracle PeopleSoft was actively exploited for ransomware attacks between late May and early June, prompting a response from the US cybersecurity agency CISA.<\/strong> On 12 June 2026, CISA added vulnerability CVE-2026-35273 to its <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" style=\"color:#0098b5;text-decoration:underline;\">Known Exploited Vulnerabilities Catalog<\/a>, confirming abuse by ransomware actors. Security researchers at Mandiant attribute the attacks to the ShinyHunters group, which reportedly targeted the higher-education sector between 27 May and 9 June; Rapid7 observed exploitation at multiple customer sites. Anyone running PeopleSoft should check patch status now-not at the next maintenance window.<\/p>\n<div style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"margin:0 0 18px 0;font-size:0.95em;font-weight:800;text-transform:uppercase;letter-spacing:0.2em;color:#69d8ed;border-bottom:2px solid rgba(105,216,237,0.25);padding-bottom:12px;\">Key Takeaways<\/p>\n<ul style=\"margin:0;padding-left:22px;color:rgba(255,255,255,0.92);line-height:1.6;\">\n<li style=\"margin-bottom:10px;\"><strong style=\"color:#69d8ed;\">Actively exploited:<\/strong> CVE-2026-35273 in Oracle PeopleSoft Enterprise PeopleTools is being abused in ransomware campaigns, rated CVSS 9.8 by CISA.<\/li>\n<li style=\"margin-bottom:10px;\"><strong style=\"color:#69d8ed;\">No login required:<\/strong> The flaw enables unauthenticated code execution according to advisories; attackers need no valid credentials.<\/li>\n<li><strong style=\"color:#69d8ed;\">Agencies face deadline:<\/strong> CISA mandated US federal agencies via BOD 26-04 to remediate by 15 June. For operators in DACH, this is a clear prompt to check your own estate immediately.<\/li>\n<\/ul>\n<\/div>\n<p style=\"font-size:0.88em;color:#666;margin:20px 0 32px 0;border-top:1px solid #e5e5e5;border-bottom:1px solid #e5e5e5;padding:10px 0;\"><span style=\"color:#0098b5;font-weight:700;text-transform:uppercase;font-size:0.72em;letter-spacing:0.14em;margin-right:14px;\">Related:<\/span><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/06\/04\/patch-prioritization-cvss-overwhelming-soc\/\" style=\"color:#333;text-decoration:underline;\">Patch Prioritization: Why CVSS Alone Overwhelms the SOC<\/a>&nbsp;&nbsp;<span style=\"color:#ccc;\">\/<\/span>&nbsp;&nbsp;<a href=\"https:\/\/www.securitytoday.de\/en\/2026\/06\/06\/when-the-backup-server-itself-becomes-the-vulnerability\/\" style=\"color:#333;text-decoration:underline;\">When the Backup Server Itself Becomes the Vulnerability<\/a><\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Why this flaw is so dangerous<\/h2>\n<p>CVE-2026-35273 resides in Oracle PeopleSoft Enterprise PeopleTools, affecting versions 8.61 and 8.62 according to multiple reports. Technically, it is a missing authentication for a critical function that in practice chains server-side request forgery to code execution. The CVSS score of 9.8 places it at the top of the scale.<\/p>\n<p>The decisive factor is the word unauthenticated. Attackers need no stolen credentials and no login hurdle to clear. An exposed, unpatched PeopleSoft instance is enough. Because PeopleSoft often manages HR, finance and student data in many organizations, the potential impact is correspondingly severe.<\/p>\n<p>The technical chain explains why the flaw is so effective. Server-side request forgery coerces the vulnerable server into making requests to targets the attacker cannot reach directly-such as internal services behind the firewall. Combined with the missing authentication, this becomes a lever that extends from outside to execution of arbitrary code on the server. This concatenation of individual weaknesses into a continuous attack path turns a missing authentication into remote code execution.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Who\u2019s attacking and who\u2019s already been hit<\/h2>\n<p>Mandiant attributes the observed exploitation to the group ShinyHunters, tracked internally as UNC6240. According to the researchers, the attack window ran from 27 May to 9 June 2026-before a broad patch was available. That makes the gap a true zero-day: exploited before defenders could react.<\/p>\n<p>The focus was initially on the higher-education sector. Universities often run PeopleSoft for administration and student management, making them attractive targets. The attacks culminated in ransomware, i.e., encryption and extortion. What started at universities can be applied to any organisation with an exposed PeopleSoft instance.<\/p>\n<div style=\"background:#e9f6f9;border-radius:8px;padding:22px 26px;margin:28px 0;\">\n<p style=\"margin:0 0 6px;font-size:0.72em;font-weight:700;text-transform:uppercase;letter-spacing:0.14em;color:#0098b5;\">The gap in numbers<\/p>\n<p style=\"margin:0;color:#23303f;line-height:1.7;\"><strong style=\"font-size:1.15em;color:#003340;\">CVSS 9.8<\/strong> &nbsp;critical rating, unauthenticated code execution.<br \/>\n<strong style=\"font-size:1.15em;color:#003340;\">12 June<\/strong> &nbsp;added to CISA\u2019s Known Exploited Vulnerabilities catalog.<br \/>\n<strong style=\"font-size:1.15em;color:#003340;\">15 June<\/strong> &nbsp;CISA patch deadline for U.S. federal agencies.<\/p>\n<\/div>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Why the CISA deadline matters for DACH too<\/h2>\n<p>The mandatory deadline for U.S. federal agencies expired on 15 June, as set out in CISA Binding Operational Directive 26-04. Yet the catalog entry remains relevant everywhere. It officially confirms the flaw is being actively exploited. A theoretical risk has become a documented attack. Risk ratings shift: an unpatched system is now seen as a likely target, not a latent residual risk.<\/p>\n<p>For German operators, regulatory obligations add weight. Entities subject to NIS2 must already demonstrate vulnerability management and response readiness. Leaving a publicly known, actively exploited gap unpatched would be hard to justify in a real incident. The CISA catalog therefore serves as a useful prioritisation aid for patch management well beyond U.S. borders.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What operators should do now<\/h2>\n<p>Step one is an inventory: is any instance of PeopleSoft Enterprise PeopleTools running and exposed to the internet? Step two is applying Oracle\u2019s <a href=\"https:\/\/www.oracle.com\/security-alerts\/alert-cve-2026-35273.html\" style=\"color:#0098b5;text-decoration:underline;\">security update<\/a>, prioritised over regular maintenance cycles. Where an immediate patch isn\u2019t possible, restrict application reachability and gate access behind additional controls.<\/p>\n<p>Step three is assuming the worst. Given exploitation since late May, every exposed instance must be checked for compromise before patching. A blind update can overwrite traces without evicting an already embedded attacker. For guidance on prioritising vulnerabilities beyond raw CVSS scores, see the analysis on <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/06\/04\/patch-prioritization-cvss-overwhelming-soc\/\" style=\"color:#0098b5;text-decoration:underline;\">patch prioritisation in the SOC<\/a>.<\/p>\n<p>Concrete compromise checks include: scanning web-server and application logs for anomalous requests to PeopleSoft components, reviewing newly created accounts and altered permissions, auditing outbound connections to unknown destinations, and hunting for web shells. Any findings warrant an incident response, not routine patching, with clean restoration from validated backups. A pre-prepared backup and disaster-recovery strategy then determines downtime in a crisis.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Frequently Asked Questions<\/h2>\n<h3>Which systems are affected by CVE-2026-35273?<\/h3>\n<p>Oracle PeopleSoft Enterprise PeopleTools-specifically versions 8.61 and 8.62, according to multiple advisories. Always verify against Oracle\u2019s official advisory for your environment.<\/p>\n<h3>Why is this gap so critical?<\/h3>\n<p>Because, per the advisories, it can be exploited without authentication and leads to code execution. The CVSS score of 9.8 reflects that severity. A reachable, unpatched instance is all an attacker needs.<\/p>\n<h3>Who\u2019s behind the attacks?<\/h3>\n<p>Mandiant attributes the observed exploitation to the group ShinyHunters, internally designated UNC6240. The attack window spanned 27 May to 9 June 2026, initially targeting the higher-education sector.<\/p>\n<h3>Does the CISA deadline also apply in Germany?<\/h3>\n<p>Formally, the deadline only binds US federal agencies. Yet the entry in the catalogue is an official confirmation of active exploitation and therefore serves as a clear prioritisation guide for DACH operators-especially under NIS2.<\/p>\n<h3>Is patching enough?<\/h3>\n<p>Patching is mandatory, but with a flaw exploited since late May it\u2019s not sufficient. Every exposed instance must be checked for signs of compromise; otherwise an already embedded attacker will remain undetected.<\/p>\n<h2 style=\"margin-top:44px;margin-bottom:18px;\">Further Reading<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/06\/05\/3-2-1-1-0-restore-test\/\" style=\"color:#0098b5;text-decoration:underline;\">Backup Against Ransomware: 3-2-1-1-0 Instead of 3-2-1<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/29\/the-edge-device-as-a-ransomware-gateway-why-mfa-at-the-vpn-is-not-enough\/\" style=\"color:#0098b5;text-decoration:underline;\">Edge Device as Ransomware Gateway: Why MFA at the VPN Matters<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/06\/08\/api-security-the-blind-spot-behind-every-integration\/\" style=\"color:#0098b5;text-decoration:underline;\">API Security: The Blind Spot Behind Every Integration<\/a><\/li>\n<\/ul>\n<h3 style=\"margin:40px 0 12px 0;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.18em;color:#666;\">More from the MBF Media Network<\/h3>\n<div style=\"display:flex;flex-direction:column;gap:12px;margin-bottom:8px;\">\n<div style=\"border-left:3px solid #0bb7fd;background:#fafafa;padding:12px 16px;\"><span style=\"display:block;font-size:0.7em;font-weight:700;text-transform:uppercase;letter-spacing:0.12em;color:#0bb7fd;margin-bottom:4px;\">cloudmagazin<\/span><a href=\"https:\/\/www.cloudmagazin.com\/2026\/06\/10\/cloud-repatriation-wann-rueckholen-rechnet\/\" style=\"color:#222;text-decoration:none;font-weight:600;\">Cloud Repatriation: When Bringing Workloads Back Makes Sense<\/a><\/div>\n<div style=\"border-left:3px solid #202528;background:#fafafa;padding:12px 16px;\"><span style=\"display:block;font-size:0.7em;font-weight:700;text-transform:uppercase;letter-spacing:0.12em;color:#202528;margin-bottom:4px;\">MyBusinessFuture<\/span><a href=\"https:\/\/mybusinessfuture.com\/545-prozent-nutzen-ki-und-der-mittelstand-haengt-trotzdem-hinten\/\" style=\"color:#222;text-decoration:none;font-weight:600;\">54.5 % Use AI-Yet SMEs Still Trail Behind<\/a><\/div>\n<div style=\"border-left:3px solid #d65663;background:#fafafa;padding:12px 16px;\"><span style=\"display:block;font-size:0.7em;font-weight:700;text-transform:uppercase;letter-spacing:0.12em;color:#d65663;margin-bottom:4px;\">Digital Chiefs<\/span><a href=\"https:\/\/www.digital-chiefs.de\/wenn-die-ki-ihre-eigenen-nachfolger-baut\/\" style=\"color:#222;text-decoration:none;font-weight:600;\">When AI Builds Its Own Successors<\/a><\/div>\n<\/div>\n<p style=\"text-align:right;font-style:italic;color:#666;\"><em>Image source: AI-generated (June 2026)<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"A critical Oracle PeopleSoft vulnerability (CVE-2026-35273) has reportedly been exploited in ransomware attacks, according to CISA.","protected":false},"author":50,"featured_media":17920,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"PeopleSoft Oracle vulnerability","_yoast_wpseo_title":"Oracle PeopleSoft: actively exploited vulnerability, CISA warns","_yoast_wpseo_metadesc":"Critical Oracle PeopleSoft flaw (CVE-2026-35273) exploited in ransomware attacks. Patch now to secure your systems!","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/06\/oracle-peoplesoft-aktiv-ausgenutzte-luecke-cisa-warnt-cover-hero.jpg","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/06\/oracle-peoplesoft-aktiv-ausgenutzte-luecke-cisa-warnt-cover-hero.jpg","_yoast_wpseo_twitter-image-id":0,"_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":[],"footnotes":""},"categories":[3,2],"tags":[],"class_list":["post-17926","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-aktuelles","category-innovation"],"evm_reading_time_minutes":6,"wpml_language":"en","wpml_translation_of":17919,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/17926","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/50"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=17926"}],"version-history":[{"count":1,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/17926\/revisions"}],"predecessor-version":[{"id":17927,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/17926\/revisions\/17927"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/17920"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=17926"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=17926"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=17926"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}