Vulnerabilities · 91 days ago

PeopleSoft Zero-Day Exposes More Victims Than Named

Public victim lists are too small to be trusted here. A PeopleSoft flaw can turn the HR system itself into a way to reach payroll, tax, and banking records, so the real exposure is broader than the few organizations that have already gone public.

Nissan has now confirmed it was targeted in the CVE-2026-35273 campaign against Oracle PeopleSoft PeopleTools. The disclosure says attackers may have reached employee data for current and former staff in the US, Canada, Mexico, and Brazil, including SSNs, banking information, and financial and tax records, and reporting says only a handful of the 100-plus targeted organizations have been named so far.

That leaves a simple assumption broken: if your PeopleSoft environment was hit, absence from the public victim list does not mean absence from the campaign. For HR and payroll operators, the question is whether employee identity and banking data were reachable before the flaw was patched.

CVE-2026-35273

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Known ransomware campaign use. EPSS 9% (95th percentile).

CISA federal remediation date Jun 15 · date passed

Timeline

Sources

2 sources covering this story

Entities

Part of the PlainSec briefing for 2026-07-01

Editions

Related stories