securityonline.info 6/12/2026, 3:01:40 AM · external

ShinyHunters hits education via Oracle PeopleSoft CVE-2026-35273

ShinyHunters hits education via Oracle PeopleSoft CVE-2026-35273
Developing story vulnerability 5 articles tracked
Oracle patches critical PeopleSoft RCE flaw (CVE-2026-35273)
CyberSIXT Evidence Panel
Primary Source cloud.google.com
CISA KEV Not in KEV
Patch Patch Status Unknown
Threat Actor

A cyberattack launched by the ShinyHunters group has targeted over 100 global organizations, particularly in the higher education sector, utilizing a critical exploit in Oracle PeopleSoft (CVE-2026-35273) that allows remote code execution with a CVSS score of 9.8. Security experts uncovered extensive reconnaissance operations where attackers mapped internal network configurations and deployed malicious scripts, leading to significant data breaches.

The attackers used a staged environment to facilitate attacks, and the campaign resulted in the leak of sensitive data on the ShinyHunters Data Leak Site. To combat the threat, organizations are urged to disable vulnerable services, monitor traffic, and secure their systems against potential ransomware attacks.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline