CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 377

As cited

Copy frozen at (site build).

vulnerabilities

Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)

Oracle released an emergency patch on June 10, 2026 for CVE-2026-35273, a critical server-side request forgery vulnerability in PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 that allows unauthenticated remote code execution. The vulnerability was actively exploited in the wild by UNC6240 (ShinyHunters) for nearly two weeks before Oracle's advisory, primarily targeting higher education institutions, with stolen data published on the attacker's leak site on June 9, 2026. Post-exploitation activity included deployment of remote management tools masquerading as Azure services and exfiltration of PeopleSoft configuration data.

Why it matters: If your organization runs PeopleTools 8.61 or 8.62, apply the emergency patch immediately; this vulnerability is actively exploited in the wild and has a 9.8 CVSS score with no authentication required.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)

Oracle released an emergency patch on June 10, 2026 for CVE-2026-35273, a critical server-side request forgery vulnerability in PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 that allows unauthenticated remote code execution. The vulnerability was actively exploited in the wild by UNC6240 (ShinyHunters) for nearly two weeks before Oracle's advisory, primarily targeting higher education institutions, with stolen data published on the attacker's leak site on June 9, 2026. Post-exploitation activity included deployment of remote management tools masquerading as Azure services and exfiltration of PeopleSoft configuration data.

Why it matters: If your organization runs PeopleTools 8.61 or 8.62, apply the emergency patch immediately; this vulnerability is actively exploited in the wild and has a 9.8 CVSS score with no authentication required.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary