Cyber Alerts

MA-1461.062026: MyCERT Advisory - Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability

Verified Officially confirmed

Recently, Oracle released security updates to address a critical vulnerability (CVE-2026-35273) in Oracle PeopleSoft PeopleTools.

First observed
29 Jul 2026
Last checked
01 Aug 2026
Evidence records
1
Publication state
Published

What happened?

Current assessment

Recently, Oracle released security updates to address a critical vulnerability (CVE-2026-35273) in Oracle PeopleSoft PeopleTools.

Why it matters

This vulnerability is remotely exploitable without authentication. If successfully exploited, this vulnerability may results in remote code execution.

Who is affected?

Affected products and groups

  • Product: Please click on the links in the Patch Availability Document column below to access the documentation for patch availability information and installation instructions. — Product or product group named in the MyCERT advisory.

What should you do now?

Actions from official guidance

For everyone

  1. CyberSecurity Malaysia encourages users and administrators to review Oracle’s Security Advisory and apply the necessary updates. Official source
  2. Generally, we advise users to be updated with the latest security announcements by the vendor and follow best practice security policies to determine which updates should be applied. Official source

Which sources support it?

Evidence and official sources

  1. MyCERTOfficial source
    MA-1461.062026: MyCERT Advisory - Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability

    Recently, Oracle released security updates to address a critical vulnerability (CVE-2026-35273) in Oracle PeopleSoft PeopleTools.

    Published Just published · Retrieved 01 Aug 2026