Critical CVE-2026-35273, CVE-2026-46817, CVE-2026-21962, CVE-2024-21182 — Four Oracle vulnerabilities were confirmed exploited in 2026: an unauthenticated PeopleTools takeover used by ransomware, an E-Business Suite Payments takeover, a CVSS 10 WebLogic proxy plug-in flaw, and a WebLogic T3/IIOP bug. Which Critical Patch Updates fix them.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: Oracle ERP and middleware servers are being attacked: PeopleSoft PeopleTools 8.61/8.62 can be taken over without credentials (CVSS 9.8, known ransomware use; out-of-band Security Alert), E-Business Suite Payments 12.2.3–12.2.15 likewise, and the WebLogic Server Proxy Plug-in for Apache/IIS rates CVSS 10. Apply the relevant Security Alert and Critical Patch Updates and keep these systems off the open internet.
| CVE-2026-35273 | PeopleSoft PeopleTools 8.61, 8.62 (Updates Environment Management): unauthenticated HTTP takeover. CVSS 9.8. Known ransomware use. Security Alert; KEV 2026-06-12 |
|---|---|
| CVE-2026-46817 | E-Business Suite Oracle Payments 12.2.3–12.2.15 (File Transmission): unauthenticated takeover. CVSS 9.8. May 2026 CSPU; KEV 2026-07-15 |
| CVE-2026-21962 | Oracle HTTP Server / WebLogic Proxy Plug-in for Apache & IIS 12.2.1.4, 14.1.1, 14.1.2. CVSS 10. January 2026 CPU; KEV 2026-08-24 |
| CVE-2024-21182 | WebLogic Server 12.2.1.4, 14.1.1 via T3/IIOP: unauthenticated data access. CVSS 7.5. July 2024 CPU; KEV 2026-06-01 |
SELECT TOOLSREL FROM PSSTATUS;SELECT RELEASE_NAME FROM APPS.FND_PRODUCT_GROUPS;$ORACLE_HOME/inventory or run opatch lspatches to see which CPU patches are applied.| CVE | Apply |
|---|---|
| CVE-2026-35273 | Oracle Security Alert for CVE-2026-35273 (PeopleTools 8.61/8.62 patches) |
| CVE-2026-46817 | May 2026 Critical Security Patch Update for E-Business Suite (or later) |
| CVE-2026-21962 | January 2026 Critical Patch Update for Fusion Middleware (or later): update the proxy plug-in on every web server |
| CVE-2024-21182 | July 2024 Critical Patch Update for WebLogic (or later) |
Oracle’s cumulative quarterly CPUs include previous fixes, so being current on the latest CPU covers the older ones.
Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.