www.rapid7.com 6/12/2026, 2:21:00 PM · external

Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)

Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)
Developing story campaign 9 articles tracked
ShinyHunters exploits Oracle PeopleSoft zero-day (CVE-2026-35273) in education sector
CyberSIXT Evidence Panel
Primary Source oracle.com
CISA KEV Not in KEV
Patch Patch Status Unknown
Threat Actor

ON June 10, 2026, Oracle announced a critical security vulnerability (CVE-2026-35273) affecting PeopleSoft Enterprise PeopleTools. The vulnerability, which could allow remote code execution without authentication, has a CVSS score of 9.8. Active exploitation was detected in the wild prior to the public disclosure, impacting mainly the higher education sector.

The attack was attributed to a financially motivated group, ShinyHunters, which successfully exploited the flaw using techniques such as server-side request forgery. Organizations using affected versions are strongly advised to apply the emergency patch and consider additional protective measures such as disabling specific services and monitoring traffic.

View Primary Source Via www.rapid7.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline