☕ This Week’s Focus
Tuesday’s CSPU pre-release already put PeopleSoft back on the patch list. Integration Broker is still how you get owned.
Oracle published the September 2026 Critical Security Patch Update pre-release. Headline number: 714 new security patches. PeopleSoft row: 16 patches, 4 remotely exploitable without authentication, ceiling 8.8. PeopleTools 8.61–8.63 are still listed. VirtualBox is back too — version 7.2.16.
That lands Tuesday, September 15. Two days after this Digest. Last month’s IB finding did not age out because you were busy with AI slides.
Let’s get into it.
🔐 Sep 15 Is Not Optional Homework
🔗 Oracle Critical Security Patch Update Advisory — September 2026 Pre-Release (Oracle) https://www.oracle.com/security-alerts/cspusep2026.html
Pre-release for the Tuesday, September 15, 2026 CSPU. 714 new security patches across the product families named in the announcement. Numbers can still move before the full advisory. PeopleSoft executive summary in the same document: 16 new security patches; 4 remotely exploitable without authentication; highest CVSS 8.8. Products named: PeopleSoft Enterprise PeopleTools 8.61–8.63, plus CC Common Application Objects 9.2, FIN Engineering Brazil 9.1, FIN Inventory Brazil 9.1, and PRTL Interaction Hub 9.1. Virtualization: Oracle VM VirtualBox 7.2.16.
🔗 Critical Patch Updates, Critical Security Patch Updates, Security Alerts and Bulletins (Oracle) https://www.oracle.com/security-alerts/
Confirms the CSPU cadence and the live pre-release listing for September 2026. Next four security Tuesdays from the same page after Sep 15: 20 October 2026 (CPU), 17 November 2026 (CSPU), 15 December 2026 (CSPU), 16 February 2027 (CSPU). August 2026 CSPU remains Rev 4, 4 September 2026.
My read: Pre-release is the planning document. If your CAB still waits for the full matrix on Tuesday morning, you are inventing a two-day delay Oracle already removed. Put PeopleTools 8.61–8.63 and VirtualBox 7.2.16 on the agenda before the advisory posts.
🧰 Integration Broker Did Not Stop Being the Path
🔗 CVE-2026-60831 (Tenable) https://www.tenable.com/cve/CVE-2026-60831
August 18, 2026 disclosure. PeopleSoft Enterprise PeopleTools, component: Integration Broker. Versions 8.61–8.63. Unauthenticated attacker with network access via HTTP. Successful attacks can result in takeover. CVSS 3.1 8.1 — AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. Fixed in the August CSPU.
🔗 Oracle Critical Security Patch Update Advisory — August 2026 (Oracle) https://www.oracle.com/security-alerts/cspuaug2026.html
Still live at Rev 4 as of September 4, 2026. 943 new security patches across the listed product families. PeopleSoft Enterprise PeopleTools 8.61–8.63 remain on the affected-products list. Next security Tuesday from that advisory: 15 September 2026 (CSPU).
🔗 Oracle Ships Its Largest Monthly Security Update (Waratek) https://waratek.com/news/oracle-largest-monthly-security-update/
August 19, 2026 analysis of the August CSPU risk matrices. PeopleSoft tally: 15 patches, 7 unauthenticated, ceiling 9.8. The 9.8 is CVE-2026-60821 in Business Interlink. Two further unauthenticated issues in the integration layer: CVE-2026-60831 in Integration Broker at 8.1, and CVE-2026-60742 in PIA Core Technology at 8.1. Waratek notes Integration Broker is reached through the /PSIGW/ path that appeared in published indicators for the ShinyHunters campaign — so shops that hardened those endpoints in June still need to verify the controls after patching.
🔗 PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM (Trend Micro) https://www.trendmicro.com/en/research/26/f/PeopleTools.html
June 18, 2026 technical write-up of CVE-2026-35273 (CVSS 9.8). The entry point that mattered: unauthenticated POST /PSIGW/HttpListeningConnector, then an SSRF pivot into the internal PSEMHUB hub. First recommendation after patching: take the listening connector off untrusted networks and put the Integration Broker gateway behind controls that restrict who can reach it.
My read: August closed one IB CVE. June’s campaign already proved /PSIGW/ is the door adversaries try first. “We patched CVE-2026-35273” is not the same sentence as “IB is boring.” Exposure review, node auth, and routing inventory are still the compensating controls.
💸 The Tax Calendar Did Not Move for CSPU Week
🔗 PeopleSoft Payroll for North America Tax Update 26-C Delivery Moves to September (Oracle / Anne Leung) https://blogs.oracle.com/peoplesoft/peoplesoft-payroll-for-north-america-tax-update-26-c-delivery-moves-to-september
August 20, 2026. Tax Update 26-C targeted for Wednesday, September 30, 2026 via the HCM Weekly PRP. HCM Image 56 (November target) carries Tax Update 26-D (first year-end set). Weekly HCM PRPs continue through December 2026 and January 2027. Bookmark MOS FAQ2322.
My read: Same finding as Ed.34 and Ed.35. Sep 15 is security Tuesday. Sep 30 is payroll Wednesday. If your change calendar only tracks Images, both arrive as surprises.
💬 Aaron’s Take
Oracle did not hide the calendar. Pre-release named PeopleSoft. August already named Integration Broker. Three concrete things this week:
Treat Tuesday’s CSPU as a PeopleTools event, not a Database event. Pre-release: 16 PeopleSoft patches, 4 unauthenticated, ceiling 8.8, PeopleTools 8.61–8.63 listed. Put it on the CAB before the full advisory posts.
Prove August’s IB patch is actually installed — then re-check
/PSIGW/. CVE-2026-60831 is Integration Broker, unauthenticated HTTP, CVSS 8.1, versions 8.61–8.63. Waratek and Trend both point at the gateway path. If HttpListeningConnector is still internet-reachable, you still have an exposure finding.Keep Sep 30 (26-C) on the same whiteboard as Sep 15. Weekly PRP, not an Image. Bookmark FAQ2322.
Thursday is five ways to make Integration Broker boring again — exposure, patch proof, ANONYMOUS, node auth, and keystore defaults turned into artifacts.
This is not a “PeopleSoft is old” problem. It is an attack-surface-management problem. The vendor publishes the door. Your shop still owes the lock inventory.
🌐 Join the Community
Subscribe to PeopleSoft Cloud for the Monday Digest and Thursday practitioner posts — no vendor spin, just what changed and what to do about it.
✅ Monday: what moved in the PeopleSoft, Oracle and ERP world, with a read on why it matters
✅ Thursday: five verifiable actions you can run this week, free, every week
✅ Written by a practitioner who still has to make the change window



