As cited
Copy frozen at (site build).
vulnerabilities
PeopleSoft 0-day affecting hundreds of organizations steals gigabytes of data
The ransomware group ShinyHunters exploited a critical server-side request forgery (SSRF) vulnerability in Oracle's PeopleSoft software (CVE-2026-35273, CVSS 9.8) to target approximately 100 customers and conduct extortion attacks. The vulnerability was actively exploited for over two weeks before Oracle disclosed it, and victims have received extortion demands from the threat actors. Oracle has released a temporary mitigation but a full patch has not yet been released.
Why it matters: This critical SSRF vulnerability in widely deployed PeopleSoft instances is actively exploited by a major ransomware group; apply available mitigations immediately and prioritize patching once Oracle releases a full fix.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
PeopleSoft 0-day affecting hundreds of organizations steals gigabytes of data
The ransomware group ShinyHunters exploited a critical server-side request forgery (SSRF) vulnerability in Oracle's PeopleSoft software (CVE-2026-35273, CVSS 9.8) to target approximately 100 customers and conduct extortion attacks. The vulnerability was actively exploited for over two weeks before Oracle disclosed it, and victims have received extortion demands from the threat actors. Oracle has released a temporary mitigation but a full patch has not yet been released.
Why it matters: This critical SSRF vulnerability in widely deployed PeopleSoft instances is actively exploited by a major ransomware group; apply available mitigations immediately and prioritize patching once Oracle releases a full fix.
- Source published
- First seen by Cybersecurity Tracker