FeedVulnerabilityOracle mitigates PeopleSoft zero-day exploited in data theft...
VulnerabilityBleeping Computer
9.8CRITICAL

Oracle mitigates PeopleSoft zero-day exploited in data theft attacks

📅 11 June 2026 at 19:39 UTC📰 Bleeping ComputerView original source ↗
Oracle mitigates PeopleSoft zero-day exploited in data theft attacks

Oracle is warning about a critical PeopleSoft Suite zero-day vulnerability tracked as CVE-2026-35273 that allows unauthenticated remote code execution, with the flaw actively exploited in ShinyHunter data theft attacks. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

A zero-day vulnerability in Oracle PeopleSoft PeopleTools (CVE-2026-35273) was exploited by the ShinyHunters threat actor, resulting in data theft attacks targeting over 100 organizations with 300 compromised instances.

⚙️Technical Details
Affected Systems
Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62
💥Impact Assessment
Severity: Critical
Who Is at Risk
Organizations running Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62
🛡️Recommended Actions
1Analyze logs for connections from IP addresses 142.11.200[.]186 to 142.11.200[.]190 and 108.174.202[.]99 to 176.120.22[.]24
2Apply emergency mitigations released by Oracle for CVE-2026-35273
3Monitor for suspicious activity and implement additional security measures
📦Affected Products
Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62
🔐NVD Verified DataVERIFIED
CVE-2026-35273CVSS 9.8CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-306

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer
← Back to feed