logo

CVE-2026-35273: Critical Oracle PeopleSoft RCE Exploited in the Wild

ID: 53237f80-59e7-540f-acae-4db4943d51ac

STIX ID: report--53237f80-59e7-540f-acae-4db4943d51ac

Feed Name: CosmicBytez Labs

Threat Score
92/100

Date Published: 2026-06-11

Date Updated: 2026-06-12

...
...

**CVE-2026-35273** is a critical (CVSS 9.8) unauthenticated remote code execution flaw in Oracle PeopleSoft PeopleTools (8.61, 8.62) affecting the Updates Environment Management component; it has been actively exploited by the ShinHunters group, including a breach at the University of Nottingham exposing over 450,000 student records, and Oracle released an emergency patch. Recommended actions include applying Oracle's patch immediately, restricting network access to affected endpoints, reviewing logs for anomalous HTTP requests, rotating credentials, and auditing connected databases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.