CISA Adds Critical Oracle PeopleSoft Vulnerability to KEV Catalog
CISA's addition of CVE-2026-35273 to the Known Exploited Vulnerabilities Catalog demonstrates the critical importance of proactive vulnerability management for enterprise systems. The vulnerability in Oracle PeopleSoft Enterprise PeopleTools is being actively exploited in the wild, posing immediate risks to organizations using this widely-deployed HR and financial management platform. Federal agencies are now mandated under BOD 26-04 to prioritize remediation, but all organizations should treat KEV-listed vulnerabilities as emergency patches. This incident highlights how enterprise business applications can become high-value targets for attackers seeking to access sensitive organizational data.
Tactical Insight
Immediate actions
- Apply Oracle security patches for PeopleSoft Enterprise PeopleTools immediately
- Scan all PeopleSoft instances for indicators of compromise
- Restrict network access to PeopleSoft systems to authorized users only
Long-term improvements
- Establish automated monitoring of CISA KEV Catalog updates
- Implement emergency patching procedures with defined SLAs for critical vulnerabilities
- Maintain comprehensive asset inventory of all enterprise applications
Detection measures
- Deploy continuous vulnerability scanning on all internet-facing enterprise systems
- Configure SIEM alerts for suspicious activity on PeopleSoft platforms