Critical Security Flaws in Oracle and Ivanti

Let me ask you something: when you walked into your office this morning, did you check the locks?

Of course you did. It’s second nature. You lock the front door, you set the alarm, and you probably have a mental checklist of making sure the windows are shut tight before you head home for the weekend.

But what if I told you that while you were double-checking the deadbolt, someone was sliding a master key under your digital back door?

That’s exactly what’s happening right now with two major pieces of software that many businesses rely on: Oracle PeopleSoft and Ivanti Sentry.

The Cybersecurity and Infrastructure Security Agency (CISA) just released an urgent update for June 17, 2026, and if your business uses these tools, you need to pay attention. This isn't just a "maybe" situation – hackers are already using these flaws to break into systems.

At Platinum Web Services, we believe you shouldn’t have to stay up at night worrying about digital lock-picking. Here is everything you need to know about these new threats and how to keep your business safe.

The Open Door in Your PeopleSoft System

Imagine you have a high-security vault. To get in, you need a fingerprint, a passcode, and a physical key. But then, you discover a tiny maintenance hatch on the side of the building that someone forgot to label. If you crawl through that hatch, you’re suddenly inside the vault – no codes required.

That is essentially what’s happening with CVE-2026-35273 in Oracle PeopleSoft.

Professional server room symbolizing enterprise infrastructure

This is what tech folks call a "Remote Code Execution" (RCE) flaw. In plain English? It means a hacker can sit in a coffee shop halfway across the world, send a specific type of message to your server, and suddenly they are running the show.

They don't need a username. They don't need a password. They just need to know your system is there.

Why This is Getting Scary

The "shocker" here isn't just that the hole exists; it’s that people are already using it. Research shows that a group known as ShinyHunters (a name that sounds much friendlier than they actually are) has been exploiting this since late May.

They aren't just looking around, either. They are planting "digital spies" inside systems – specifically something called MeshCentral agents. These agents allow the hackers to stay inside your network even after you think you’ve kicked them out.

If your business handles HR data, financial records, or sensitive employee information through PeopleSoft, this vulnerability is like leaving your filing cabinet wide open on the sidewalk.

The Hidden Threat in Your Network Gateway

While Oracle is dealing with the PeopleSoft mess, Ivanti is facing its own fire. Their tool, Ivanti Sentry, has a critical flaw identified as CVE-2026-10520.

Think of Ivanti Sentry as the security guard standing at the entrance to your private company network. It’s supposed to check IDs and make sure only the right people get through.

Networking hardware representing secure gateways

Here’s the problem: CISA has added this flaw to their "Known Exploited Vulnerabilities" catalog. That means this isn't a theoretical math problem – real hackers are actively using this to bypass security.

When your "security guard" is the one being tricked, your entire network is at risk. This is how ransomware starts. This is how data breaches that make the evening news begin. It's why predictive patching is so vital for modern businesses.

Platinum Insight: What This Means for You

"If you use Oracle PeopleSoft or Ivanti Sentry, you are currently in a race against time. Hackers have already started running; you need to make sure your defenses are moving faster."

For most small business owners, reading about "SSRF-to-RCE chains" is about as interesting as reading a toaster manual in a foreign language. We get it. You have a business to run.

But here is the bottom line: These vulnerabilities allow attackers to bypass all your normal login screens. If you haven't updated your systems in the last 48 hours, you might already have a "digital squatter" in your network.

This is exactly why we emphasize proactive managed IT services. Waiting for something to break is a strategy that worked in 1998. In 2026, you need to fix the hole before the water starts coming in.

Technical Summary

For the IT managers and technical leads reading this, here are the nuts and bolts of the CISA advisory:

CVE-2026-35273 (Oracle PeopleSoft)

  • Component: PeopleTools (Updates Environment Management), versions 8.61 and 8.62.
  • Type: SSRF-to-RCE (Server-Side Request Forgery leading to Remote Code Execution).
  • CVSS Score: 9.8 (Critical).
  • Attack Vector: Unauthenticated HTTP requests to /PSEMHUB/hub and /PSIGW/HttpListeningConnector.
  • Exploitation Status: Active zero-day exploitation confirmed. Attackers are using this to capture NetNTLM hashes and deploy persistent backdoors.

CVE-2026-10520 (Ivanti Sentry)

  • Impact: Known to be exploited in the wild.
  • Action Required: Immediate update to the latest vendor-provided patch.
  • Risk: Potential for unauthorized network access and lateral movement.

So, What Can You Do?

If you're feeling a bit overwhelmed, take a breath. It’s not about blame – it’s about awareness. Here is your immediate action plan:

  • Patch Immediately: This isn't a "do it next Tuesday" task. If you run PeopleSoft 8.61 or 8.62, apply the Oracle Security Alert patches right now.
  • Check Your Logs: Look for any weird activity around the /PSEMHUB/hub endpoint. If you see connections you don't recognize, it’s time to call in the pros.
  • Restrict Exposure: If your PeopleSoft or Ivanti Sentry systems are sitting on the open internet where anyone can find them, move them behind a VPN. Don't make it easy for the bad guys.
  • Hunt for "Squatters": Look for unusual processes on your servers, especially anything related to "MeshCentral" or files that look like Azure updates but aren't (meshagent64-azure-ops.exe).

Turn Your Weakest Link Into Your Strongest Defense

At Platinum Web Services, we see these alerts every single day. We know how frustrating it is to feel like the goalposts are always moving. You just want your technology to work so you can focus on your customers.

Platinum Web Services IT specialist monitoring security

The truth is, cyber security isn't a "one and done" project. It’s a living, breathing part of your business. But you don't have to carry that burden alone. Whether it's 24/7 support for IT emergencies or a complete overhaul of your cyber security solutions, we are here to help.

We help businesses like yours with this every day, ensuring that your digital "locks" are always updated and your "vaults" remain secure.

If you’d like help checking your systems for these flaws or want to move to a proactive strategy that stops these problems before they start, get in touch with us at Platinum Web Services. Let’s make sure your business stays your business.

0 Comments