Skip to main content

Oracle mitigates PeopleSoft zero-day exploited in data theft attacks

  • June 11, 2026
  • 0 replies
  • 21 views

Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

June 11, 2026, By Lawrence Abrams

 

Hand sifting data

Oracle is warning about a critical PeopleSoft Suite zero-day vulnerability tracked as CVE-2026-35273 that allows unauthenticated remote code execution, with the flaw actively exploited in ShinyHunter data theft attacks.

The flaw is within Oracle PeopleSoft PeopleTools and has a CVSS base score of 9.8.

"This Security Alert addresses vulnerability CVE-2026-35273 in Oracle PeopleSoft PeopleTools. Oracle PeopleSoft Enterprise Applications customers may also be affected by this vulnerability," reads a new Oracle advisory.

"This vulnerability is remotely exploitable without authentication. If successfully exploited, this vulnerability may result in remote code execution."

Oracle has confirmed that the zero-day vulnerability affects PeopleSoft Enterprise PeopleTools, versions 8.61 and 8.62, and has released emergency mitigations to address the flaw, with a patch coming soon.

 

>>Full Article<<