Vulnerabilities & Exploits · Ransomware

Oracle Middleware Fixes Stack Up as PeopleSoft Lingers

Oracle’s June CSPU is more than a bulk maintenance release. The problem is the mix: Oracle has a large patch wave, but the actively exploited PeopleSoft issue is still overdue, and unpatched Fusion Middleware stays the easiest remotely reachable path into Oracle estates.

Oracle says the June 16 CSPU covers 243 CVEs in 245 updates across 11 product families. Fusion Middleware accounts for 106 of those fixes, and the KEV-listed PeopleSoft flaw, CVE-2026-35273, remains past deadline after being exploited in the wild as a zero-day.

That leaves Oracle environments facing two separate pressures at once: an overdue exploited bug and a dense cluster of network-reachable middleware fixes. The patch count is not the story; the exposed admin and middleware surface is.

15 sources · Jun 19

CVE-2026-35273

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Known ransomware campaign use. EPSS 9% (95th percentile).

CISA federal remediation date Jun 15 · date passed

Timeline

Sources

Part of the PlainSec briefing for 2026-06-11

Every edition of this story: Oracle Middleware Fixes Stack Up as PeopleSoft Lingers

More from today