NCSC-2026-0195 [1.00] [M/H] Vulnerability fixed in Oracle PeopleSoft Enterprise PeopleTools
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Oracle has fixed a vulnerability in Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62. The vulnerability allows unauthenticated attackers to exploit the system remotely via HTTP. This can lead to remote code execution, potentially resulting in full system takeover. The vulnerability affects Oracle PeopleSoft Enterprise PeopleTools and is particularly exploitable when the PeopleSoft Environment Management Hub (PSEMHUB) is accessible from the internet. It is common to make such management components accessible only through internal networks or a VPN. Google CTI reports that this vulnerability has been exploited as a zero-day since at least May 27.
CSIRTS triage
- What
- The vulnerability allows unauthenticated attackers to execute remote code.
- Who is affected
- Deployments of Oracle PeopleSoft Enterprise PeopleTools with PSEMHUB accessible from the internet are affected.
- Urgency
- Immediate remediation is critical as this vulnerability has been exploited as a zero-day.
- Action
- Update to the patched versions of PeopleTools.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch PeopleSoft Enterprise PeopleTools
Get an email when a new PeopleSoft Enterprise PeopleTools advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0195
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-35273Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99.9% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-35273 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from NCSC-NL Advisories
- unknownNCSC-2026-0303 [1.01] [M/H] Vulnerabilities patched in GitLab by GitLab Inc.2026-08-25
- unknownNCSC-2026-0326 [1.00] [M/H] Vulnerabilities patched in Keycloak2026-08-25
- unknownNCSC-2026-0325 [1.00] [M/H] Vulnerabilities patched in Atlassian products2026-08-24
- unknownNCSC-2026-0324 [1.00] [M/H] Vulnerability fixed in Zimbra Collaboration Suite2026-08-23
- unknownNCSC-2026-0323 [1.00] [M/H] Vulnerabilities fixed in Cisco Secure Workload2026-08-21