• News/
  • bleepingcomputer-20260611193953

Oracle mitigates PeopleSoft zero-day exploited in data theft attacks

BleepingComputer
·
Lawrence Abrams
·
Published Jun 11, 2026
·
Updated

Oracle is warning about a critical PeopleSoft Suite zero-day vulnerability tracked as CVE-2026-35273 that allows unauthenticated remote code execution, with the flaw actively exploited in ShinyHunter data theft attacks. The flaw is within Oracle PeopleSoft PeopleTools and has a CVSS base score of 9.8. "This Security Alert addresses vulnerability CVE-2026-35273 in Oracle PeopleSoft PeopleTools. Oracle PeopleSoft Enterprise Applications customers may also be affected by this vulnerability," reads a new Oracle advisory. "This vulnerability is remotely exploitable without authentication. If successfully exploited, this vulnerability may result in remote code execution." Oracle has confirmed that the zero-day vulnerability affects PeopleSoft Enterprise PeopleTools, versions 8.61 and 8.62, and has released emergency mitigations to address the flaw, with a patch coming soon. While Oracle has not stated that this vulnerability is actively exploited, its disclosure comes after BleepingComputer first reported that the ShinyHunters extortion gang was exploiting a PeopleSoft zero-day vulnerability to breach instances and steal data. BleepingComputer has since learned that this is the zero-day exploited in the attacks. On Tuesday, BleepingComputer learned that Oracle PeopleSoft was targeted in a wave of data theft attacks that left ransom notes purportedly from the ShinyHunters extortion gang. ShinyHunters is a well-known threat actor that commonly breaches cloud SaaS instances, CRMs, an...

Read full article

Affected Software

2 affected components
Oracle PeopleSoft PeopleTools=8.61, =8.62
Oracle PeopleSoft Enterprise Applications
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical zero-day vulnerability in Oracle PeopleSoft that is actively being exploited in data theft attacks.

2

What is the name and CVE identifier of the vulnerability?

The vulnerability is tracked as CVE-2026-35273.

3

What type of attacks is this vulnerability being exploited in?

The vulnerability is being exploited in ShinyHunter data theft attacks.

4

What is the CVSS base score of the vulnerability?

The vulnerability has a CVSS base score of 9, indicating its critical severity.

5

Which Oracle products are affected by this vulnerability?

The affected products are Oracle PeopleSoft PeopleTools and Oracle PeopleSoft Enterprise Applications.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203