Oracle Middleware Fixes Stack Up as PeopleSoft Lingers
Oracle’s June CSPU is more than a bulk maintenance release. The problem is the mix: Oracle has a large patch wave, but the actively exploited PeopleSoft issue is still overdue, and unpatched Fusion Middleware stays the easiest remotely reachable path into Oracle estates.
Oracle says the June 16 CSPU covers 243 CVEs in 245 updates across 11 product families. Fusion Middleware accounts for 106 of those fixes, and the KEV-listed PeopleSoft flaw, CVE-2026-35273, remains past deadline after being exploited in the wild as a zero-day.
That leaves Oracle environments facing two separate pressures at once: an overdue exploited bug and a dense cluster of network-reachable middleware fixes. The patch count is not the story; the exposed admin and middleware surface is.
De kwetsbaarheden in Oracle PeopleSoft Enterprise PT PeopleTools versies 8.61 en 8.62 stellen ongeauthenticeerde aanvallers met netwerktoegang via HTTP of HTTPS in...