VulnerabilityBleeping Computer
9.8 — CRITICAL
Oracle mitigates PeopleSoft zero-day exploited in data theft attacks
Oracle is warning about a critical PeopleSoft Suite zero-day vulnerability tracked as CVE-2026-35273 that allows unauthenticated remote code execution, with the flaw actively exploited in ShinyHunter data theft attacks. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
A zero-day vulnerability in Oracle PeopleSoft PeopleTools (CVE-2026-35273) was exploited by the ShinyHunters threat actor, resulting in data theft attacks targeting over 100 organizations with 300 compromised instances.
⚙️Technical Details
Affected Systems
Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62
💥Impact Assessment
Severity: Critical
Who Is at Risk
Organizations running Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62
🛡️Recommended Actions
1Analyze logs for connections from IP addresses 142.11.200[.]186 to 142.11.200[.]190 and 108.174.202[.]99 to 176.120.22[.]24
2Apply emergency mitigations released by Oracle for CVE-2026-35273
3Monitor for suspicious activity and implement additional security measures
📦Affected Products
Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62
🔐NVD Verified DataVERIFIED
CVE-2026-35273 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-306
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
