logo

ShinyHunters Exploits Oracle PeopleSoft Zero-Day Vulnerability

ID: 864b7619-5f29-55aa-8905-b3a9ec9adabe

STIX ID: report--864b7619-5f29-55aa-8905-b3a9ec9adabe

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-06-11

Date Updated: 2026-06-12

...
...

**Executive summary:** A critical unauthenticated remote-code-execution zero-day (CVE-2026-35273) in Oracle PeopleSoft was actively exploited by the ShinyHunters group between May 27 and June 9, 2026, resulting in breaches of over 100 organizations—primarily educational institutions—and the publication of stolen data including approximately 500,000 student records; Oracle issued an advisory on June 10 and recommends immediate mitigation although no official patch is yet available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.