CVE-2026-35273: Critical Oracle PeopleSoft RCE Exploited in the Wild
ID: 53237f80-59e7-540f-acae-4db4943d51ac
STIX ID: report--53237f80-59e7-540f-acae-4db4943d51ac
Feed Name: CosmicBytez Labs
**CVE-2026-35273** is a critical (CVSS 9.8) unauthenticated remote code execution flaw in Oracle PeopleSoft PeopleTools (8.61, 8.62) affecting the Updates Environment Management component; it has been actively exploited by the ShinHunters group, including a breach at the University of Nottingham exposing over 450,000 student records, and Oracle released an emergency patch. Recommended actions include applying Oracle's patch immediately, restricting network access to affected endpoints, reviewing logs for anomalous HTTP requests, rotating credentials, and auditing connected databases.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
