Accenture, acting as a contractor for the FBI, allegedly failed to install updates for Oracle Peoplesoft after CVE-2026-35273 was published.
This was a "Missing Authentication for Critical Function" vulnerability and scored 9.8. If this didn't raise any flags, the CISA KEV listing should have. It was an n-day at release.
But no, interestingly enough the FBI is exempt from BOD 26-04 and wasn't even obliged to update?!
Man, if not even federal agencies fix their vulns, this is all pointless.