<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/oracle-drops-245-patches-with-active-peoplesoft-rce-node-js-fixes-11-cves-across-all-active-lines-drurui8qb" -->

---
title: Oracle drops 245 patches with active PeopleSoft RCE,...
description: Oracle&#x27;s June 2026 Critical Patch Update delivers 245 patches covering 243 CVEs, with a pre-auth RCE zero-day in PeopleSoft PeopleTools (CVE-2026-35273, CVSS...
canonical: https://daily.dev/posts/oracle-drops-245-patches-with-active-peoplesoft-rce-node-js-fixes-11-cves-across-all-active-lines-drurui8qb
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Oracle drops 245 patches with active PeopleSoft RCE, Node.js fixes 11 CVEs across all active lines | daily.dev
og:description: Oracle&#x27;s June 2026 Critical Patch Update delivers 245 patches covering 243 CVEs, with a pre-auth RCE zero-day in PeopleSoft PeopleTools (CVE-2026-35273, CVSS...
og:url: https://daily.dev/posts/oracle-drops-245-patches-with-active-peoplesoft-rce-node-js-fixes-11-cves-across-all-active-lines-drurui8qb
og:image: https://api.daily.dev/og/posts/druRUi8qB.png
og:image:alt: Oracle drops 245 patches with active PeopleSoft RCE, Node.js fixes 11 CVEs across all active lines
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Oracle drops 245 patches with active PeopleSoft RCE, Node.js fixes 11 CVEs across all active lines

**[Security Digest](https://daily.dev/sources/security_digest)** · 5 min read · 1 upvotes · 0 comments

## Summary

Oracle's June 2026 Critical Patch Update delivers 245 patches covering 243 CVEs, with a pre-auth RCE zero-day in PeopleSoft PeopleTools (CVE-2026-35273, CVSS 9.8) already exploited by ShinyHunters against 100+ organizations. WebLogic and Oracle Coherence carry separate CVSS 10.0 unauthenticated flaws. Node.js released coordinated security updates across all three active lines (22, 24, 26), each patching 11 CVEs including a high-severity TLS hostname normalization flaw. The Klue OAuth breach has expanded: the 'Icarus' group used stolen OAuth tokens to automate Salesforce CRM data exfiltration via Python scripts, with Huntress confirmed as a victim. Additional coverage includes Gentlemen ransomware's BYOVD-based EDR killer targeting CrowdStrike and SentinelOne, pgAdmin 4 unauthenticated RCE via pickle deserialization, critical NGINX HTTP/3 RCE CVEs, npm v12 blocking major malicious attack vectors by default, and GitHub Actions checkout v7 blocking pwn-request attacks.

## Content

**TLDR:** Oracle's June 2026 CPU lands with 245 patches, and CVE-2026-35273 — a pre-auth RCE in PeopleSoft PeopleTools — was already being exploited in the wild by ShinyHunters before the patch dropped. WebLogic and Oracle Coherence carry CVSS 10.0 flaws requiring no authentication, making them immediate ransomware targets. Node.js pushed coordinated security releases across all three active lines (22 LTS, 24 LTS, 26 Current) patching 11 CVEs each, including a high-severity TLS hostname normalization flaw. The Klue OAuth breach has expanded: the 'Icarus' threat group used compromised OAuth tokens to automate Salesforce CRM exfiltration across multiple organizations including Huntress.

---

## Oracle June 2026 CPU: 245 patches, CVSS 10.0 WebLogic flaws, PeopleSoft zero-day already exploited

Oracle's June 2026 Critical Patch Update covers 243 CVEs across 245 patches, with nearly half rated critical. The most urgent is CVE-2026-35273 (CVSS 9.8) in PeopleSoft PeopleTools 8.61 and 8.62 — a pre-auth RCE chain exploiting the PSIGW Integration Broker via SSRF into an internal management servlet, then achieving code execution through Java XMLDecoder deserialization. ShinyHunters (SHADOW-AETHER-015) was actively exploiting it from May 27, hitting over 100 organizations, mostly in higher education. The attack runs entirely inside the WebLogic JVM with no child process spawned and no outbound beacon, making behavioral and network detection largely blind. WebLogic Server and Oracle Coherence carry separate CVSS 10.0 unauthenticated flaws. Patch immediately, restrict PSIGW network exposure, and treat web-tier restarts as security-relevant events. [Read more](https://app.daily.dev/feed-by-ids?id=AIuT2JPUE&id=F19sJr0EU&id=OANSHrtv4)

## Node.js 22, 24, and 26 all patch 11 CVEs in coordinated security releases

Node.js pushed security-only releases across all three active lines — 22.23.0 LTS, 24.17.0 LTS, and 26.3.1 Current — each addressing the same 11 CVEs. The two high-severity fixes are CVE-2026-48618 (TLS hostname normalization for server identity checks) and CVE-2026-48933 (WebCrypto cipher output length guard). Medium-severity fixes cover HTTP/2 unbounded memory growth, NUL byte injection in DNS and net hostnames, proxy credential leakage in tunnel errors, and TLS session binding to authenticated hosts. OpenSSL was updated to 3.5.7 across all lines. If you're running any Node.js version in production, this is a straightforward update with no API changes. [Read more](https://app.daily.dev/feed-by-ids?id=HP8Siu0Zv&id=djrgVDQY2&id=8FMsqbwyZ)

## Klue OAuth breach: 'Icarus' group automated Salesforce CRM exfiltration across multiple victims

The Klue breach disclosed by Recorded Future has more depth than the initial notification suggested. Attackers compromised Klue's backend, pushed a malicious code update to steal OAuth tokens, then ran automated Python scripts against Salesforce REST APIs to pull CRM data — contacts, sales communications, price quotes, and competitive intelligence — from multiple organizations. Huntress confirmed it was among the victims and received extortion emails. Salesforce has disabled the Klue Battlecards integration while the investigation continues. Affected organizations should review SaaS logs for suspicious IPs, revoke and rotate all OAuth tokens tied to Klue, and audit Salesforce API activity for anomalous queries. [Read more](https://app.daily.dev/feed-by-ids?id=XLxkpsXoU&id=o3rZPffHd)

## Gentlemen ransomware deploys eight EDR-killer variants targeting CrowdStrike, SentinelOne, and Microsoft

ESET researchers detailed the Gentlemen RaaS group's tooling, which centers on GentleKiller — a BYOVD-based EDR killer with at least eight variants that impersonate legitimate security products to gain kernel-level privileges and terminate over 400 processes across roughly 48 security vendors. For redundancy and attribution complexity, the group also deploys three external killers (HexKiller, ThrottleBlood, HavocKiller) plus a Rust-based credential stealer called OxideHarvest. Target selection is based on FortiGate endpoint configurations, which is particularly concerning given the FortiBleed credential leak exposing 74,000 FortiGate VPN credentials covered in yesterday's digest. [Read more](https://app.daily.dev/posts/w7uzUEvxr)

---

## Also notable

- **pgAdmin 4 v9.16 patches seven CVEs including unauthenticated RCE via pickle deserialization:** pgAdmin 4 v9.16 fixes CVE-2026-12044 through CVE-2026-12050, covering SQL injection in dialog templates, an AI Assistant bypass enabling RCE via COPY TO PROGRAM, unauthenticated SQL Editor endpoints with a pickle deserialization sink, and stored XSS allowing credential exfiltration — update immediately if you run pgAdmin in any shared or network-accessible environment. [Read more](https://app.daily.dev/posts/43lcqxnYC)
- **F5 out-of-band patches for critical NGINX CVEs: unauthenticated RCE via HTTP/3 and gRPC modules:** CVE-2026-42530 and CVE-2026-42055 in NGINX's HTTP/3 and proxy/gRPC modules allow unauthenticated remote attackers to trigger denial-of-service or RCE via use-after-free and heap buffer overflow, particularly on systems with ASLR disabled — temporary mitigations exist for NGINX Plus and Open Source if immediate patching isn't possible. [Read more](https://app.daily.dev/posts/fSoYcAzfR)
- **npm v12 (July 2026) blocks lifecycle scripts, Git deps, and remote URLs by default — covers ~53% of malicious npm attack vectors:** JFrog research found these three vectors were involved in roughly 53% of malicious npm attacks over the past year; npm v12 requires explicit opt-in via allowScripts, --allow-git, and --allow-remote flags, raising the bar significantly while pushing attackers toward compromising already-trusted packages instead. [Read more](https://app.daily.dev/posts/2D4pdCF9o)
- **GitHub actions/checkout v7 blocks 'pwn request' attacks by default, enforcement backported July 16:** The new version refuses to fetch fork PR code in pull_request_target and workflow_run contexts when insecure refs are used; on July 16, 2026, this enforcement backports to all supported major versions, automatically affecting workflows pinned to floating major tags — audit your workflows before that date. [Read more](https://app.daily.dev/posts/cs5C6Qtly)
- **Accenture acquires Dragos, runZero, and NetRise for $4.18bn on the same day its stock dropped 20%:** The three acquisitions focus on OT security for critical infrastructure; the move signals Accenture pivoting toward harder-to-automate security segments as AI threatens its core consulting revenue, with total acquisition budget raised to $9bn for the year. [Read more](https://app.daily.dev/posts/YXNsL83fA)

## Similar posts on daily.dev

- [Oracle releases 245 new security patches, all rated ‘high-priority security’](https://daily.dev/posts/oracle-releases-245-new-security-patches-all-rated-high-priority-security--aiut2jpue) · CSO Online · 1 upvotes · 0 comments
- [Oracle Critical Security Patch Update June 2026](https://daily.dev/posts/oracle-critical-security-patch-update-june-2026-oanshrtv4) · Tenable Blog · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#nodejs](https://daily.dev/tags/nodejs), [#oracle](https://daily.dev/tags/oracle), [#oauth](https://daily.dev/tags/oauth)

[View this post on daily.dev](https://daily.dev/posts/oracle-drops-245-patches-with-active-peoplesoft-rce-node-js-fixes-11-cves-across-all-active-lines-drurui8qb)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"DiscussionForumPosting","mainEntityOfPage":"https://daily.dev/posts/oracle-drops-245-patches-with-active-peoplesoft-rce-node-js-fixes-11-cves-across-all-active-lines-drurui8qb","headline":"Oracle drops 245 patches with active PeopleSoft RCE, Node.js fixes 11 CVEs across all active lines","text":"Oracle's June 2026 Critical Patch Update delivers 245 patches covering 243 CVEs, with a pre-auth RCE zero-day in PeopleSoft PeopleTools (CVE-2026-35273, CVSS 9.8) already exploited by ShinyHunters against 100+ organizations. WebLogic and Oracle Coherence carry separate CVSS 10.0 unauthenticated flaws. Node.js released coordinated security updates across all three active lines (22, 24, 26), each patching 11 CVEs including a high-severity TLS hostname normalization flaw. The Klue OAuth breach has expanded: the 'Icarus' group used stolen OAuth tokens to automate Salesforce CRM data exfiltration via Python scripts, with Huntress confirmed as a victim. Additional coverage includes Gentlemen ransomware's BYOVD-based EDR killer targeting CrowdStrike and SentinelOne, pgAdmin 4 unauthenticated RCE via pickle deserialization, critical NGINX HTTP/3 RCE CVEs, npm v12 blocking major malicious attack vectors by default, and GitHub Actions checkout v7 blocking pwn-request attacks.","url":"https://daily.dev/posts/oracle-drops-245-patches-with-active-peoplesoft-rce-node-js-fixes-11-cves-across-all-active-lines-drurui8qb","datePublished":"2026-06-19T04:18:05.984Z","dateModified":"2026-09-13T20:59:35.448Z","author":{"@type":"Organization","name":"Security Digest","logo":"https://media.daily.dev/image/upload/s--m4ZKB_C0--/f_auto,q_auto/v1779959612/logos/security_digest","url":"https://daily.dev/sources/security_digest"},"interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"isPartOf":{"@type":"WebPage","url":"https://daily.dev/sources/security_digest","name":"Security Digest"}}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Security Digest","item":"https://daily.dev/sources/security_digest"},{"@type":"ListItem","position":3,"name":"Oracle drops 245 patches with active PeopleSoft RCE, Node.js fixes 11 CVEs across all active lines"}]}
```

