Oracle PeopleSoft CVE-2026-35273 Is Exploited: Patch PeopleTools 8.61 and 8.62
Oracle PeopleSoft PeopleTools CVE-2026-35273: active exploitation, known ransomware use, unauthenticated takeover, CVSS 9.8, on CISA KEV. Who is affected and what to do.
Oracle PeopleSoft Enterprise PeopleTools CVE-2026-35273 is under active exploitation, and CISA flags it for known ransomware campaign use. Oracle’s Security Alert describes the flaw as remotely exploitable without authentication, with a successful attack resulting in remote code execution; Oracle’s risk matrix scores it CVSS 9.8 and points to the Updates Environment Management component reached over HTTP. NVD and the CVE List record it as missing authentication for a critical function (CWE-306). CISA added it to the Known Exploited Vulnerabilities catalog on June 12, 2026, two days after Oracle’s June 10 alert. Treat any internet-reachable PeopleTools 8.61 or 8.62 as a compromise risk now, not later.
Am I affected?
In Oracle’s words, the affected products are “PeopleSoft Enterprise PeopleTools, versions 8.61, 8.62,” and Oracle adds that PeopleSoft Enterprise Applications customers may also be affected. The vulnerable surface is the Updates Environment Management component, reached over HTTP without authentication.
Two questions decide your exposure:
- Do you run PeopleTools 8.61 or 8.62, or a PeopleSoft Enterprise Application on top of them?
- Is the Environment Management Hub (
/PSEMHUB/hub) or the Integration Gateway (/PSIGW/HttpListeningConnector) reachable from the public internet or from untrusted networks?
If both are true, assume you were exposed in the window between first exploitation and your patch. VulnMonitor answers the first question from your live inventory, so you are not grepping configuration by hand under time pressure.
What to do now
- Patch first. Oracle’s fix ships through the Security Alert for CVE-2026-35273: apply it from the PeopleSoft Patch Availability Document on My Oracle Support (Oracle reference CPU187). Oracle strongly recommends immediate action and lists no alternative workaround, so the patch is the fix. The CISA federal remediation due date is June 15, 2026, a useful deadline for any organization, not just agencies.
- Until the patch is in, cut the exposed surface. Keep the Environment Management Hub (
/PSEMHUB/hub) and the Integration Gateway (/PSIGW/HttpListeningConnector) off the public internet and off untrusted networks, and disable the EMHub Service or remove the PSEMHUB application if you do not use it. The honest cost: disabling EMHub stops environment management and update synchronization, so confirm your patch and maintenance workflows first. - Assume pre-patch exposure and hunt. For an unauthenticated RCE on an internet-facing service, any time the endpoints were reachable before patching is time they could have been hit. Review PSEMHUB.war directories for unexpected
.jspfiles, watch for unexpected outbound connections, and follow the CISA BOD 26-04 forensic requirements referenced in the KEV required action.
How it is being exploited
CISA’s KEV listing is the exploitation confirmation. The catalog records CVE-2026-35273 with a date added of June 12, 2026, a remediation due date of June 15, 2026, and known ransomware campaign use marked “Known.” Oracle published its Security Alert on June 10, 2026 (Rev 1) and credits the report to researchers working through the Zero Day Initiative, so the fix and the in-the-wild use surfaced within days of each other.
EPSS for this CVE is 22.21 percent (96th percentile) as of June 13, 2026, and is expected to move as more data arrives on a fresh, actively exploited flaw.
For indicators of compromise and the latest exploitation detail, work from the primary trackers: Oracle’s advisory and CISA’s KEV entry. We are not naming any victim organization, because none has been confirmed by the victim or a regulator.
How VulnMonitor helps
VulnMonitor keeps a live inventory of what you run, so the first question above answers itself: you already know whether any PeopleTools instance is on 8.61 or 8.62, and whether its endpoints are exposed. When a CVE lands on KEV, VulnMonitor reconciles it against that inventory and ranks it by KEV status and EPSS, so an unauthenticated takeover like this one surfaces at the top of your queue within the hour rather than in next week’s scan. It does not stop the attack itself, so the patch above is still the action that closes the risk.
Updates
- 2026-06-13, 15:00 UTC Initial post. CVE-2026-35273 added to CISA KEV on June 12, 2026, with known ransomware campaign use. CVSS 9.8, EPSS 22.21 percent (96th percentile, June 13). Affected: PeopleTools 8.61 and 8.62.