A critical Oracle PeopleSoft vulnerability (CVE-2026-35273, CVSS 9.8) enables unauthenticated remote code execution through Java deserialization in the PSEMHUB component. Over 1,300 affected instances were identified via FOFA scanning in the past year.