Critical Oracle PeopleSoft Vulnerability Actively Exploited in ShinyHunters Campaign
ID: 17b95fdf-0859-514d-8f55-2bfa0fb2a6bb
STIX ID: report--17b95fdf-0859-514d-8f55-2bfa0fb2a6bb
Feed Name: Arctic Wolf Blog
Threat Score
A critical unauthenticated remote code execution vulnerability in Oracle PeopleSoft PeopleTools (CVE-2026-35273, CVSS 9.8) is being actively exploited by the ShinyHunters extortion group in a global data-theft campaign affecting hundreds of instances; Oracle published an out-of-band security alert and customers are urged to apply the vendor patch immediately or implement temporary network/WAF mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
