CVE Tools

Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters

SecurityWeekBy Eduard Kovacs

Reported exploitedPeopleSoft Enterprise PeopleToolsShinyHuntersPeopleSoft Enterprise Applications

Our summary

Google confirmed that ShinyHunters has exploited an Oracle-mitigated PeopleSoft flaw as a zero-day for data theft. The issue is tracked as CVE-2026-35273, a critical unauthenticated remote code execution vulnerability affecting PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62, along with PeopleSoft Enterprise Applications, where Oracle released an out-of-band advisory and mitigations but patches do not appear to be available. Mandiant and Google Threat Intelligence Group observed activity tied to the exploitation from May 27 to June 9, with targeting reportedly concentrated in education and the University of Nottingham named as a confirmed victim.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store