Oracle released its June 2026 Critical Security Patch Update (CSPU), addressing 243 CVEs across 245 security patches in 11 product families. Nearly half (49.8%) of patches are rated critical severity. Oracle Fusion Middleware received the most patches at 106 (43.3%), followed by Oracle E-Business Suite at 55. A notable highlight is CVE-2026-35273, a zero-day remote code execution vulnerability in Oracle PeopleSoft Enterprise PeopleTools that was actively exploited in the wild by the extortion group ShinyHunters (UNC6240), affecting over 100 organizations globally — 68% of which were in the higher education sector. Organizations are urged to apply all relevant patches immediately.
Table of contents
Key TakeawaysBackgroundAnalysisOracle PeopleSoft zero-day exploitedSolutionIdentifying affected systems593 Impressions