#1
BleepingComputer
general
June 11, 2026 at 19:39 UTC
Oracle mitigates PeopleSoft zero-day exploited in data theft attacks
By Lawrence Abrams
AI Summary
Oracle's PeopleSoft Suite contains CVE-2026-35273, a critical unauthenticated remote code execution zero-day being actively exploited by ShinyHunters in ongoing data theft campaigns targeting hundreds of organizations, including universities. Oracle has released a mitigation but has not publicly confirmed the vulnerability's in-the-wild exploitation status, leaving defenders in an uncertain patch posture. Security practitioners should treat this as a critical priority given Google's confirmation of active exploitation and the scope of affected institutions.
Relevance score: 95.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →