Oracle is warning about a critical PeopleSoft Suite zero-day vulnerability tracked as CVE-2026-35273 that allows unauthenticated remote code execution, with the flaw actively exploited in ShinyHunter data theft attacks. The flaw is within Oracle PeopleSoft PeopleTools and has a CVSS base score of 9.8. "This Security Alert addresses vulnerability CVE-2026-35273 in Oracle PeopleSoft PeopleTools. Oracle PeopleSoft Enterprise Applications customers may also be affected by this vulnerability," reads a new Oracle advisory. "This vulnerability is remotely exploitable without authentication. If successfully exploited, this vulnerability may result in remote code execution." Oracle has confirmed that the zero-day vulnerability affects PeopleSoft Enterprise PeopleTools, versions 8.61 and 8.62, and has released emergency mitigations to address the flaw, with a patch coming soon. While Oracle has not stated that this vulnerability is actively exploited, its disclosure comes after BleepingComputer first reported that the ShinyHunters extortion gang was exploiting a PeopleSoft zero-day vulnerability to breach instances and steal data. BleepingComputer has since learned that this is the zero-day exploited in the attacks. On Tuesday, BleepingComputer learned that Oracle PeopleSoft was targeted in a wave of data theft attacks that left ransom notes purportedly from the ShinyHunters extortion gang. ShinyHunters is a well-known threat actor that commonly breaches cloud SaaS instances, CRMs, an...
Oracle mitigates PeopleSoft zero-day exploited in data theft attacks
BleepingComputer
·Lawrence Abrams
·Published Jun 11, 2026
·Updated
Affected Software
2 affected components
Oracle PeopleSoft PeopleTools=8.61, =8.62
Oracle PeopleSoft Enterprise Applications
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical zero-day vulnerability in Oracle PeopleSoft that is actively being exploited in data theft attacks.
2
What is the name and CVE identifier of the vulnerability?
The vulnerability is tracked as CVE-2026-35273.
3
What type of attacks is this vulnerability being exploited in?
The vulnerability is being exploited in ShinyHunter data theft attacks.
4
What is the CVSS base score of the vulnerability?
The vulnerability has a CVSS base score of 9, indicating its critical severity.
5
Which Oracle products are affected by this vulnerability?
The affected products are Oracle PeopleSoft PeopleTools and Oracle PeopleSoft Enterprise Applications.