---
schema: 1
kind: vulnerability
title: "CVE-2026-46978 / CVE-2026-35278 — Oracle June 2026 CSPU: unauthenticated Solaris RAD flaw (CVSS 10.0) and PeopleSoft RCE (9.8)"
headline: "CVE-2026-46978 / CVE-2026-35278 — Oracle June 2026 CSPU: unauthenticated Solaris RAD flaw (CVSS 10.0) and PeopleSoft RCE (9.8)"
summary: "Oracle June 2026 Critical Security Patch Update ships 245 fixes, ~100 remotely exploitable without authentication. The standouts: CVE-2026-46978 (Solaris 11.4 Remote Administration Daemon, CVSS 10.0) and CVE-2026-35278 (PeopleSoft PeopleTools Performance Monitor, CVSS 9.8), both unauthenticated (SecurityWeek, 2026-06-17 · Oracle, 2026-06-17). No confirmed exploitation yet — patch internet-facing tiers first."
discovered_at: "2026-06-18T05:10:31Z"
event_date: 2026-06-17
run_id: 2026-06-18-aa7ee817
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - rce
  - pre-auth
  - patch-available
regions:
  - global
sectors:
  - public-sector
  - finance
entities: []
cves:
  - id: CVE-2026-46978
    cvss: "10.0"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
  - id: CVE-2026-35278
    cvss: "9.8"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
sources:
  - url: "https://www.oracle.com/security-alerts/cspujun2026.html"
    publisher: Oracle CSPU advisory
    role: primary
  - url: "https://www.securityweek.com/oracles-second-monthly-security-updates-deliver-245-patches/"
    publisher: SecurityWeek
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Patch the Oracle June 2026 CSPU, internet-facing tiers first** (§ 2). Prioritise the unauthenticated Solaris RAD flaw (CVE-2026-46978, CVSS 10.0) and PeopleSoft Performance Monitor (CVE-2026-35278, CVSS 9.8); interim-scope the Solaris RAD daemon to localhost where remote admin is not needed."
migrated_from: briefs/2026-06-18.md
---

Oracle's June 2026 Critical Security Patch Update shipped 245 fixes on 2026-06-17, ~100 of them remotely exploitable without authentication ([SecurityWeek, 2026-06-17](https://www.securityweek.com/oracles-second-monthly-security-updates-deliver-245-patches/) · [Oracle, 2026-06-17](https://www.oracle.com/security-alerts/cspujun2026.html)). The two standouts for this audience are both pre-auth: **CVE-2026-46978** (CVSS 10.0) in the Oracle Solaris 11.4 Remote Administration Daemon (RAD), reachable by an unauthenticated attacker over its default HTTPS management interface, and **CVE-2026-35278** (CVSS 9.8), a missing-authentication RCE in PeopleSoft PeopleTools 8.61/8.62 Performance Monitor (`T1190`). Oracle reports no in-the-wild exploitation at publication; the unauthenticated network vectors warrant emergency prioritisation. Patch internet-facing PeopleSoft and middleware tiers first; as interim hardening, scope the Solaris RAD daemon to localhost where remote administration is not required.
