ZDI-26-389: Oracle PeopleSoft ExecuteProcessActivityCommand External Control of File Path Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle PeopleSoft. Although authentication is required to... 25/06/2026 Zero-Day Initiative
ZDI-26-388: Oracle PeopleSoft HubMBeanPersistance Deserialization of Untrusted Data Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle PeopleSoft. Although authentication is required to... 25/06/2026 Zero-Day Initiative
ZDI-26-387: Oracle PeopleSoft HttpListeningConnector Server-Side Request Forgery Vulnerability This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Oracle PeopleSoft. Authentication is not required... 25/06/2026 Zero-Day Initiative
ZDI-26-386: Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of Unraid. Authentication is required to exploit this... 25/06/2026 Zero-Day Initiative
ZDI-26-385: Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of Unraid. Authentication is required to exploit this... 25/06/2026 Zero-Day Initiative
ZDI-26-384: MosaicML Composer Deserialization of Untrusted Data Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of MosaicML Composer. User interaction is required to... 25/06/2026 Zero-Day Initiative
ZDI-26-383: ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of ATEN Unizon. Authentication is required to exploit... 25/06/2026 Zero-Day Initiative
CVE‑2026‑35273 — Defending Against the Oracle PeopleSoft PSEMHUB Authentication Bypass Summary CVE–2026–35273 is an actively exploited, unauthenticated remote code execution vulnerability in Oracle PeopleSoft Enterprise PeopleTools — not a routine critical–CVE patch. Oracle disclosed it on... 19/06/2026 Qualys-Threat-Protect
Oracle Critical Patch Update, June 2026 Security Update Review Oracle released its third quarterly edition of this year’s Critical Patch Update. The update received patches for 245 security vulnerabilities. Some of the... 19/06/2026 Qualys-Threat-Protect
Microsoft Defender Zero-day Vulnerability Exploited in Attacks (CVE-2026-50656) (RoguePlanet) Microsoft announced the active exploitation of a Defender zero-day named RoguePlanet. Tracked as CVE-2026-50656, successful exploitation of the vulnerability may allow an attacker to gain SYSTEM-level access. Microsoft... 19/06/2026 Qualys-Threat-Protect