logo

ShinyHunters Exploits Oracle PeopleSoft Zero-Day, Over 100 Organizations Compromised

ID: 82edb622-6fca-57a7-b76b-8c5f202f053d

STIX ID: report--82edb622-6fca-57a7-b76b-8c5f202f053d

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-06-11

Date Updated: 2026-06-12

...
...

A critical zero-day (CVE-2026-35273) in Oracle PeopleSoft is being actively exploited by the ShinyHunters group to achieve unauthenticated remote code execution and rapid data exfiltration; more than 100 organizations—primarily in the education sector—have reportedly been breached (including ~500,000 student records at the University of Nottingham), with Mandiant and others confirming attacks, proof-of-concept code public, and Oracle issuing an emergency alert but not yet a patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.