Oracle Issues Emergency Fix for PeopleSoft Zero-Day Hit by ShinyHunters
CONFIRMEDDate confidence: CONFIRMEDStated as firmHow firmly the source words the date: confirmed, scheduled, estimated, delayed or unverified.Show all CONFIRMED pins88% CONFIDENCEOverall confidence: 88%How well the pin's source and references back up its dates.Weighted average of how firmly 4 references, the source included, support the pin's start and end times; a reference counts half as much for every 180 days older than the newestShow all pins at 75% confidence or better114 days agoOracle's[1] Security Alert Advisory CVE-2026-35273 lists '2026-June-10 Rev 1. Initial Release' in its modification history.
Oracle's Security Alert for CVE-2026-35273, a 9.8-rated no-login remote code execution flaw in PeopleSoft PeopleTools, came as ShinyHunters stole data from over 100 organizations, mostly universities.