Multiple vulnerabilities in Oracle PeopleSoft (August 19, 2026)
Multiple vulnerabilities have been discovered in Oracle PeopleSoft. They allow an attacker to cause data confidentiality breach, data integrity breach and denial of service.
CSIRTS triage
- What
- Multiple vulnerabilities in Oracle PeopleSoft allow data confidentiality and integrity breaches and denial of service.
- Who is affected
- All deployments of Oracle PeopleSoft are potentially affected.
- Urgency
- High priority due to data breach and availability impact risks.
- Action
- Apply Oracle's security patches for PeopleSoft to all affected instances.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch PeopleSoft
Get an email when a new PeopleSoft advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1050/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-708610.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-608840.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-609750.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-608790.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-711120.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-609020.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-613070.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-608830.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-608210.49% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-607420.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-70861 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60884 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60975 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60879 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71112 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60902 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-61307 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60883 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60821 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60742 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60967 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71092 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60831 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60856 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60873 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0316 [1.00] [M/H] Vulnerabilities resolved in Oracle PeopleSoft Enterprisencsc-nl
- high[NEW] [high] Oracle PeopleSoft: Multiple vulnerabilitiescert-bund
- highCVE-2026-71112: Vulnerability in the PeopleSoft Enterprise FIN Common Objects product of Oracle PeopleSoft (co…nvd
- highCVE-2026-71092: Vulnerability in the PeopleSoft Enterprise FIN Lease Administration product of Oracle PeopleSo…nvd
- highCVE-2026-70861: Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleS…nvd
- highCVE-2026-61307: Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle Peo…nvd
- highCVE-2026-60975: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component…nvd
- highCVE-2026-60967: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component…nvd
- highCVE-2026-60902: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component…nvd
- mediumCVE-2026-60884: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component…nvd
- highCVE-2026-60883: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component…nvd
- highCVE-2026-60879: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component…nvd
Recent advisories for Oracle PeopleSoft
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownNCSC-2026-0316 [1.00] [M/H] Vulnerabilities resolved in Oracle PeopleSoft Enterprisencsc-nl · 2026-08-19
- high[NEW] [high] Oracle PeopleSoft: Multiple vulnerabilitiescert-bund · 2026-08-19
- highCVE-2026-71112: Vulnerability in the PeopleSoft Enterprise FIN Common Objects product of Oracle PeopleSoft (co…nvd · 2026-08-18
- highCVE-2026-71092: Vulnerability in the PeopleSoft Enterprise FIN Lease Administration product of Oracle PeopleSo…nvd · 2026-08-18
- highCVE-2026-70861: Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleS…nvd · 2026-08-18
- highCVE-2026-61307: Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle Peo…nvd · 2026-08-18
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Oracle Virtualization (August 19, 2026)2026-08-19
- unknownMultiple vulnerabilities in Oracle Weblogic (August 19, 2026)2026-08-19
- unknownMultiple vulnerabilities in Axis products (August 19, 2026)2026-08-19
- unknownMultiple vulnerabilities in Google Chrome (August 19, 2026)2026-08-19
- unknownMultiple vulnerabilities in Oracle MySQL (August 19, 2026)2026-08-19