Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

Oracle Exploited CVEs 2026: PeopleSoft CVE-2026-35273 (Ransomware), E-Business Suite, WebLogic, HTTP Server Plug-in

Critical CVE-2026-35273, CVE-2026-46817, CVE-2026-21962, CVE-2024-21182 — Four Oracle vulnerabilities were confirmed exploited in 2026: an unauthenticated PeopleTools takeover used by ransomware, an E-Business Suite Payments takeover, a CVSS 10 WebLogic proxy plug-in flaw, and a WebLogic T3/IIOP bug. Which Critical Patch Updates fix them.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: Oracle ERP and middleware servers are being attacked: PeopleSoft PeopleTools 8.61/8.62 can be taken over without credentials (CVSS 9.8, known ransomware use; out-of-band Security Alert), E-Business Suite Payments 12.2.3–12.2.15 likewise, and the WebLogic Server Proxy Plug-in for Apache/IIS rates CVSS 10. Apply the relevant Security Alert and Critical Patch Updates and keep these systems off the open internet.

CVE-2026-35273PeopleSoft PeopleTools 8.61, 8.62 (Updates Environment Management): unauthenticated HTTP takeover. CVSS 9.8. Known ransomware use. Security Alert; KEV 2026-06-12
CVE-2026-46817E-Business Suite Oracle Payments 12.2.3–12.2.15 (File Transmission): unauthenticated takeover. CVSS 9.8. May 2026 CSPU; KEV 2026-07-15
CVE-2026-21962Oracle HTTP Server / WebLogic Proxy Plug-in for Apache & IIS 12.2.1.4, 14.1.1, 14.1.2. CVSS 10. January 2026 CPU; KEV 2026-08-24
CVE-2024-21182WebLogic Server 12.2.1.4, 14.1.1 via T3/IIOP: unauthenticated data access. CVSS 7.5. July 2024 CPU; KEV 2026-06-01

What’s affected

  • PeopleSoft (CVE-2026-35273): the Updates Environment Management component of PeopleTools 8.61 and 8.62 lets an unauthenticated attacker over HTTP take over PeopleTools. Oracle issued an out-of-band Security Alert rather than waiting for the quarterly patch, and CISA marks it as used by ransomware. PeopleSoft holds HR, payroll and student records, which makes it a prime extortion target.
  • E-Business Suite (CVE-2026-46817): Oracle Payments’ File Transmission component in EBS 12.2.3–12.2.15 is takeover-able by an unauthenticated attacker over HTTP. EBS has been a repeated target of data-theft extortion campaigns.
  • WebLogic Proxy Plug-in (CVE-2026-21962): the plug-in that lets Apache HTTP Server, Oracle HTTP Server or IIS front a WebLogic cluster has a CVSS 10 flaw reachable over HTTP without authentication.
  • WebLogic T3/IIOP (CVE-2024-21182): a 2024 bug exploitable over the T3 and IIOP protocols, now confirmed exploited.

Am I affected?

  • PeopleTools version: in PIA, Help → About This Page, or SELECT TOOLSREL FROM PSSTATUS;
  • EBS version: SELECT RELEASE_NAME FROM APPS.FND_PRODUCT_GROUPS;
  • WebLogic / OHS: check $ORACLE_HOME/inventory or run opatch lspatches to see which CPU patches are applied.

How to patch

CVEApply
CVE-2026-35273Oracle Security Alert for CVE-2026-35273 (PeopleTools 8.61/8.62 patches)
CVE-2026-46817May 2026 Critical Security Patch Update for E-Business Suite (or later)
CVE-2026-21962January 2026 Critical Patch Update for Fusion Middleware (or later): update the proxy plug-in on every web server
CVE-2024-21182July 2024 Critical Patch Update for WebLogic (or later)

Oracle’s cumulative quarterly CPUs include previous fixes, so being current on the latest CPU covers the older ones.

Reduce exposure

  • Block T3/IIOP (default port 7001 and any custom listeners) from the internet. Use WebLogic connection filters to allow them only from trusted hosts.
  • Don’t expose PeopleSoft or EBS admin/integration endpoints publicly. Put self-service portals behind a WAF or reverse proxy that only allows the paths users need.
  • Review accounts and recently created users in PeopleSoft and EBS, and watch for large data exports. Recent campaigns focused on stealing data, not just encrypting it.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories