As cited
Copy frozen at (site build).
vulnerabilities
Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)
Oracle released an emergency patch on June 10, 2026 for CVE-2026-35273, a critical server-side request forgery vulnerability in PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 that allows unauthenticated remote code execution. The vulnerability was actively exploited in the wild by UNC6240 (ShinyHunters) for nearly two weeks before Oracle's advisory, primarily targeting higher education institutions, with stolen data published on the attacker's leak site on June 9, 2026. Post-exploitation activity included deployment of remote management tools masquerading as Azure services and exfiltration of PeopleSoft configuration data.
Why it matters: If your organization runs PeopleTools 8.61 or 8.62, apply the emergency patch immediately; this vulnerability is actively exploited in the wild and has a 9.8 CVSS score with no authentication required.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)
Oracle released an emergency patch on June 10, 2026 for CVE-2026-35273, a critical server-side request forgery vulnerability in PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 that allows unauthenticated remote code execution. The vulnerability was actively exploited in the wild by UNC6240 (ShinyHunters) for nearly two weeks before Oracle's advisory, primarily targeting higher education institutions, with stolen data published on the attacker's leak site on June 9, 2026. Post-exploitation activity included deployment of remote management tools masquerading as Azure services and exfiltration of PeopleSoft configuration data.
Why it matters: If your organization runs PeopleTools 8.61 or 8.62, apply the emergency patch immediately; this vulnerability is actively exploited in the wild and has a 9.8 CVSS score with no authentication required.
- Source published
- First seen by Cybersecurity Tracker