logo

Critical Oracle PeopleSoft Vulnerability Actively Exploited in ShinyHunters Campaign

ID: 17b95fdf-0859-514d-8f55-2bfa0fb2a6bb

STIX ID: report--17b95fdf-0859-514d-8f55-2bfa0fb2a6bb

Feed Name: Arctic Wolf Blog

Threat Score
90/100

Date Published: 2026-06-11

Date Updated: 2026-06-17

...
...

A critical unauthenticated remote code execution vulnerability in Oracle PeopleSoft PeopleTools (CVE-2026-35273, CVSS 9.8) is being actively exploited by the ShinyHunters extortion group in a global data-theft campaign affecting hundreds of instances; Oracle published an out-of-band security alert and customers are urged to apply the vendor patch immediately or implement temporary network/WAF mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.