logo

Oracle mitigates PeopleSoft zero-day exploited in data theft attacks

ID: 24f093d4-46df-5203-a608-fac0e3cad2a0

STIX ID: report--24f093d4-46df-5203-a608-fac0e3cad2a0

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-06-11

Date Updated: 2026-06-11

Author: Lawrence Abrams

...
...

**Oracle PeopleSoft zero-day (CVE-2026-35273) actively exploited by ShinyHunters**: A critical unauthenticated RCE (CVSS 9.8) in PeopleSoft PeopleTools (versions 8.61 and 8.62) is being used in data theft attacks affecting an estimated 300 instances across more than 100 organizations; Oracle has released emergency mitigations and will issue a patch, and the report includes attacker IP indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.