Oracle issues an out-of-band security alert after reporting that a zero-day vulnerability in Oracle PeopleSoft PeopleTools is being exploited in the wild. The flaw, identified as CVE-2026-35273, is described by Oracle as remotely exploitable without authentication and potentially leading to remote code execution. The alert points to affected installations running PeopleTools versions 8.61 and 8.62, and Oracle indicates that other, possibly earlier, unsupported versions may also be impacted.

Multiple reports describe Oracle’s guidance to patch immediately and treat the issue as urgent. One outlet also notes that threat intelligence from Charles Carmakal, CTO at Mandiant (Google Cloud), highlights the ongoing exploitation. The reporting aligns on the core technical risk—unauthenticated remote attack paths and the possibility of executing arbitrary code—and on Oracle’s response via an out-of-band notification. Together, the sources indicate that Oracle’s fix and mitigations are time-sensitive, given the continued real-world targeting of exposed PeopleSoft systems.