Home / Jun 13, 2026 / Story
0
#1 BleepingComputer general June 11, 2026 at 19:39 UTC

Oracle mitigates PeopleSoft zero-day exploited in data theft attacks

By Lawrence Abrams

AI Summary

Oracle's PeopleSoft Suite contains CVE-2026-35273, a critical unauthenticated remote code execution zero-day being actively exploited by ShinyHunters in ongoing data theft campaigns targeting hundreds of organizations, including universities. Oracle has released a mitigation but has not publicly confirmed the vulnerability's in-the-wild exploitation status, leaving defenders in an uncertain patch posture. Security practitioners should treat this as a critical priority given Google's confirmation of active exploitation and the scope of affected institutions.

Relevance score: 95.0/100

# More from June 13