Oracle Urges Immediate Software Patches as Hackers Breach PeopleSoft Servers
Summary
Oracle disclosed a remotely exploitable PeopleSoft PeopleTools flaw (CVE-2026-35273) that can enable unauthenticated remote code execution. The company urged customers to patch immediately amid indications that attackers are already breaching vulnerable PeopleSoft servers.
Why it matters
An unauthenticated RCE in a widely deployed enterprise platform can rapidly become a mass compromise vector if patch adoption lags.