Vulnerabilities & Exploits · Ransomware
Oracle Middleware Fixes Stack Up as PeopleSoft Lingers Oracle’s June CSPU is more than a bulk maintenance release. The problem is the mix: Oracle has a large patch wave, but the actively exploited PeopleSoft issue is still overdue, and unpatched Fusion Middleware stays the easiest remotely reachable path into Oracle estates.
Oracle says the June 16 CSPU covers 243 CVEs in 245 updates across 11 product families. Fusion Middleware accounts for 106 of those fixes, and the KEV-listed PeopleSoft flaw, CVE-2026-35273 , remains past deadline after being exploited in the wild as a zero-day.
That leaves Oracle environments facing two separate pressures at once: an overdue exploited bug and a dense cluster of network-reachable middleware fixes. The patch count is not the story; the exposed admin and middleware surface is.
15 sources · Jun 19
NVD KEV
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Known ransomware campaign use. EPSS 9% (95th percentile).
CISA federal remediation date Jun 15 · date passed
Timeline Sources Jun 19 CSO Online
Oracle releases 245 new security patches, all rated ‘high-priority security’
The updates apply to multiple products and also include fixes for third-party components
original Jun 18 Qualys
Oracle Critical Patch Update, June 2026 Security Update Review | Qualys
Oracle released its third quarterly edition of this year’s Critical Patch Update.
original Jun 18 Tenable
Oracle Critical Security Patch Update June 2026 | Tenable®
Oracle’s Critical Security Patch Update (CSPU) for June 2026, its second CSPU, addresses 243 CVEs, including 122 critical updates.
original Part of the PlainSec briefing for 2026-06-11
Every edition of this story: Oracle Middleware Fixes Stack Up as PeopleSoft Lingers
More from today
Vulnerabilities & Exploits · Ransomware
Oracle Middleware Fixes Stack Up as PeopleSoft Lingers Oracle’s June CSPU is more than a bulk maintenance release. The problem is the mix: Oracle has a large patch wave, but the actively exploited PeopleSoft issue is still overdue, and unpatched Fusion Middleware stays the easiest remotely reachable path into Oracle estates.
Oracle says the June 16 CSPU covers 243 CVEs in 245 updates across 11 product families. Fusion Middleware accounts for 106 of those fixes, and the KEV-listed PeopleSoft flaw, CVE-2026-35273 , remains past deadline after being exploited in the wild as a zero-day.
That leaves Oracle environments facing two separate pressures at once: an overdue exploited bug and a dense cluster of network-reachable middleware fixes. The patch count is not the story; the exposed admin and middleware surface is.
15 sources · Jun 19
NVD KEV
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Known ransomware campaign use. EPSS 9% (95th percentile).
CISA federal remediation date Jun 15 · date passed
Timeline Sources Jun 19 CSO Online
Oracle releases 245 new security patches, all rated ‘high-priority security’
The updates apply to multiple products and also include fixes for third-party components
original Jun 18 Qualys
Oracle Critical Patch Update, June 2026 Security Update Review | Qualys
Oracle released its third quarterly edition of this year’s Critical Patch Update.
original Jun 18 Tenable
Oracle Critical Security Patch Update June 2026 | Tenable®
Oracle’s Critical Security Patch Update (CSPU) for June 2026, its second CSPU, addresses 243 CVEs, including 122 critical updates.
original Part of the PlainSec briefing for 2026-06-11
Every edition of this story: Oracle Middleware Fixes Stack Up as PeopleSoft Lingers
More from today