VORANT. Threat Intelligence Sign in Get the full feed

Oracle patches 16 PeopleSoft flaws, NCSC-NL warns

elevated vulnerability

NCSC-NL advises on 16 Oracle PeopleSoft vulnerabilities, including four unauthenticated remote flaws, with patches now available.

The Dutch NCSC has published an advisory covering 16 vulnerabilities patched by Oracle across several PeopleSoft Enterprise products, including PeopleTools, the PRTL Interaction Hub, and CC Common Application Objects. The flaws stem from issues such as integer overflow, improper validation of input, improper handling of exceptional conditions, and prototype pollution. Four of the 16 vulnerabilities can be exploited remotely over the network without authentication, while others require a low-privileged account or user interaction. None of the flaws are rated critical, but several carry high CVSS scores.

The highest-scoring issue, CVE-2026-83017 (CVSS 8.8), affects the Report Distribution component of PeopleSoft Enterprise PeopleTools and requires a low-privileged account to exploit. CVE-2026-73954 (CVSS 8.1), in the Business Interlink component of PeopleTools, can be exploited remotely over HTTP without any authentication and could lead to full takeover of the affected PeopleTools instance, though Oracle notes it is difficult to exploit in practice. Successful exploitation across the set of vulnerabilities could result in unauthorized access to sensitive data, data modification, full component takeover, or denial of service.

Oracle has released updates addressing all listed vulnerabilities. There is no indication in this advisory of active exploitation in the wild. Defenders running PeopleSoft Enterprise products, particularly PeopleTools, should prioritize patching based on exposure — internet-facing or authenticated-access components tied to Business Interlink and Report Distribution should be addressed first given their remote and high-impact exploitation potential.

Mentioned in this report

Vulnerabilities CVE-2026-25639CVE-2026-73954CVE-2026-73955CVE-2026-73960CVE-2026-7598CVE-2026-82993CVE-2026-83014CVE-2026-83015CVE-2026-83016CVE-2026-83017CVE-2026-83018CVE-2026-83019CVE-2026-83070CVE-2026-87264

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0381.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free