CVE‑2026‑35273 — Defending Against the Oracle PeopleSoft PSEMHUB Authentication Bypass

Summary CVE–2026–35273 is an actively exploited, unauthenticated remote code execution vulnerability in Oracle PeopleSoft Enterprise PeopleTools — not a routine critical–CVE patch. Oracle disclosed it on June 10, 2026 in an out–of–band Security Alert, rating it CVSS 9.8 and placing it in the Updates Environment Management component. Oracle states successful exploitation may result in remote code execution; NVD describes possible takeover of PeopleSoft Enterprise PeopleTools. Reaching sensitive … Continue reading “CVE‑2026‑35273 — Defending Against the Oracle PeopleSoft PSEMHUB Authentication Bypass”

CVE-2026-50751 — Defending Against the Check Point IKEv1 VPN Authentication Bypass

Summary CVE-2026-50751 is an actively exploited authentication-bypass vulnerability in Check Point remote-access VPN — not a generic perimeter flaw. Disclosed by Check Point on June 8, 2026, it sits in deprecated IKEv1 remote-access code paths and lets an unauthenticated remote attacker establish a VPN connection without a valid user password. The confirmed impact is unauthorized VPN session establishment; … Continue reading “CVE-2026-50751 — Defending Against the Check Point IKEv1 VPN Authentication Bypass”