$ intel.mask2.ca

ADVISORY · 2026-06-13 · SRC CISA-ADVISORIES · CRITICAL
2026-06-13 critical REL 8/10

CISA Adds Oracle PeopleSoft Authentication Bypass to Known Exploited Vulnerabilities

post-secondarygovernmenthealthcarefinance

CISA has added CVE-2026-35273, an authentication bypass flaw in Oracle PeopleSoft Enterprise PeopleTools, to its Known Exploited Vulnerabilities catalog due to active exploitation. The vulnerability allows complete system compromise and is now prioritized for remediation under updated federal directive BOD 26-04. CISA encourages all organizations, not just federal agencies, to adopt risk-based vulnerability management and prioritize patching of KEV catalog entries.

Why it matters in Western Canada: Oracle PeopleSoft is widely deployed in Canadian post-secondary institutions, public sector agencies, and healthcare organizations for human resources and financial management. Organizations in BC, Alberta, Saskatchewan, and Manitoba running PeopleSoft should treat this as a high-priority remediation target given active exploitation.

CVEs: CVE-2026-35273


Summary generated from the original advisory. Read the full source: cisa-advisories

Source
https://www.cisa.gov/news-events/alerts/2026/06/12/cisa-adds-one-known-exploited-vulnerability-catalog
CVEs
CVE-2026-35273
Tags
oracle-peoplesoft, authentication-bypass, active-exploitation, critical-priority, peopletools
Provenance
mask2-ti-pipeline (AI-assisted, human-reviewable)