cbcvebase.
CVE-2026-35273
published 2026-06-11

CVE-2026-35273: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are…

PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2026-06-15
Exploited in the wild
EPSS
95.47%
99.9th percentile
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Affected

4 ranges
VendorProductVersion rangeFixed in
oraclepeoplesoft_enterprise_peopletools
oraclepeoplesoft_enterprise_peopletools
oracle_corporationpeoplesoft_enterprise_peopletools
oracle_corporationpeoplesoft_enterprise_peopletools

Detection & IOCsextracted from sources · hover to see the quote

ip176.120.22.24
domainazurenetfiles.net
urlwss://azurenetfiles.net:443/agent.ashx
hashf02a924c9ff92a8780ce812511341182c6b509d45bc59f3f7b522e37225d24fc
hashd83fdb9e53c5ff03c4cb0451ea1bebd79b53f29eadc1e2fa394c7af13a86ce2f
hashc7e9332731b06644fc73e0046a2a89eaa59b09f54250e9bd622467187351711f
hash68257a6f9ff196179ec03624e849927f26599eb180a7c82e14ef5bc4e93bc309
hash2ab684d93c1553fad87041b4dea97188a97e78589deee2a7bacff905564f3a35
filenamemeshagent64-azure-ops.exe
filenamemeshagent64-v2.exe
filenamemeshagent32-azure-ops.exe
filenameREADME-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT
path/PSEMHUB/hub
path/PSIGW/HttpListeningConnector
port445
commandnode meshctrl.js RunCommand --loginuser admin --loginpass '[password]' --id '[agent_id]' --run 'bash /tmp/[victim_abbreviation]_fanout.sh'
commandpv -s "$(du -sb exfil | awk '{print $1}')" | zstd -3 -T0 -o exfil.tar.zst
  • Alert on HTTP POST requests from external source IPs to /PSEMHUB/hub and /PSIGW/HttpListeningConnector in WebLogic access logs.
  • Flag requests to /PSIGW/HttpListeningConnector containing loopback addresses or internal IP ranges in headers or parameters as potential SSRF exploitation.
  • Hunt for unexpected .jsp files under the PSEMHUB.war web application directory as a post-exploitation indicator.
  • Hunt for unauthorized files or directories under PSEMHUB.war/envmetadata/transactions/ as a post-exploitation indicator.
  • Hunt for unexpected directories named logs, persistantstorage, or scratchpad under PSEMHUB paths.
  • Hunt for recently created or modified .xml files under /envmetadata/data/environment/ which may indicate XMLDecoder persistence that fires on server restart.
  • Monitor outbound SMB (TCP/445) from PeopleSoft hosts to external destinations; the exploit chain may coerce outbound connections to capture Windows machine-account NetNTLM hashes.
  • Detect MeshCentral agents masquerading as Azure services by hunting for processes or binaries named meshagent64-azure-ops.exe or meshagent32-azure-ops.exe with C2 to azurenetfiles.net.
  • Presence of README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT in PeopleSoft webserv or appserv directories is a definitive compromise marker.
  • TrendAI IPS Rule 1012580 and DDI Rule 5855 provide vendor detection signatures for the SSRF exploitation of CVE-2026-35273.
  • Staging servers ran Python's SimpleHTTP server on port 8888; scanning for this service on attacker IPs can help identify infrastructure.
  • ·The exploit chain is multi-stage: SSRF via /PSEMHUB/hub is chained with /PSIGW/HttpListeningConnector and XMLDecoder persistence; WAF body-inspection rules alone are insufficient as they can be bypassed.
  • ·Blocking /PSEMHUB/* and /PSIGW/HttpListeningConnector at the perimeter is considered non-breaking for standard end-user PIA browser sessions.
  • ·Exploitation predates the patch by two weeks (May 27 – June 9, 2026); organizations should hunt for compromise indicators even after patching, as XMLDecoder payloads persist and execute on next server restart.
  • ·Earlier, unsupported PeopleTools versions beyond 8.61 and 8.62 are also likely vulnerable per Oracle.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.