Unpatched Oracle PeopleSoft Zero-Day Exposes Nissan Employee Data
Threat actors exploited a critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft before Nissan could apply a patch, resulting in the exposure of highly sensitive employee data including Social Security numbers, banking details, and tax records across four countries. The scale of the attack — affecting over 300 PeopleSoft instances across 100 organizations — indicates that many enterprises failed to prioritize timely patching of internet-facing HR and payroll systems. This breach underscores the severe consequence of delayed remediation when critical business systems store regulated personal and financial data. The incident also highlights the danger of consolidating sensitive employee data in enterprise platforms without compensating controls such as network segmentation or data minimization.
Tactical Insight
Immediate actions
- Apply Oracle's emergency patch or implement vendor-recommended mitigations for CVE-2026-35273 across all PeopleSoft instances without delay.
- Restrict external network access to PeopleSoft and payroll systems to trusted IP ranges or VPN-only connections while patches are being deployed.
- Audit and rotate all credentials, API keys, and service accounts associated with affected PeopleSoft environments.
Long-term improvements
- Establish a formal emergency patching SLA (e.g., 24–72 hours) for critical vulnerabilities affecting internet-facing systems that store regulated data.
- Implement network segmentation to isolate HR, payroll, and financial systems from general corporate and internet-facing infrastructure.
- Enforce data minimization principles by purging or archiving employee records no longer needed for active business operations.
Detection measures
- Deploy continuous vulnerability scanning targeted at internet-facing enterprise applications, with automated alerts for newly disclosed critical CVEs.
- Enable behavioral anomaly detection and SIEM alerting on PeopleSoft authentication logs to identify unusual access patterns or bulk data exports.
- Subscribe to Oracle's Critical Patch Update (CPU) advisories and threat intelligence feeds to receive early warning of zero-day disclosures.