logo

U.S. CISA adds Oracle PeopleSoft Enterprise PeopleTools flaw to its Known Exploited Vulnerabilities catalog

ID: aa35b561-220a-5535-be17-481b04eb810e

STIX ID: report--aa35b561-220a-5535-be17-481b04eb810e

Feed Name: Security Affairs

Threat Score
92/100

Date Published: 2026-06-13

Date Updated: 2026-06-13

Author: Pierluigi Paganini

...
...

The report describes an active zero-day exploitation campaign (May 27–June 9, 2026) against Oracle PeopleSoft PeopleTools (CVE-2026-35273, CVSS 9.8) attributed to ShinyHunters/UNC6240: attackers used MeshCentral agents and acme-client-issued TLS certificates for C2, performed lateral movement and credential spraying, left extortion markers, and exfiltrated sensitive data (including ~455k email records); CISA added the CVE to its KEV catalog and ordered federal mitigation by June 15, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.