Blogs.Oracle ShinyHunters Exploits Oracle PeopleSoft Zero-Day Vulnerability
Article Content
- •CVE-2026-35273 allows unauthenticated remote code execution in Oracle PeopleSoft.
- •ShinyHunters has claimed over 100 breaches, including significant data theft from universities.
- •Oracle has issued an advisory but has not yet released a patch for the vulnerability.
A critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft has been exploited by the ShinyHunters group, leading to breaches of over 100 organizations, primarily in the education sector. The vulnerability allows unauthenticated remote code execution, enabling attackers to compromise systems without prior authentication. The exploitation occurred between May 27 and June 9, 2026, before Oracle's advisory was published on June 10, 2026. Mandiant confirmed that approximately 500,000 student records from the University of Nottingham were among the stolen data. Attackers utilized a 'gadget chain' of vulnerabilities to facilitate the breaches, and the stolen data has been published on the ShinyHunters Data Leak Site. Oracle has issued an urgent advisory recommending immediate patching and mitigation measures, but as of now, no official patch is available. Organizations are advised to restrict internet-facing access to vulnerable systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (65)
Following this threat?
Track Cl0p, ShinyHunters and AT&T in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Cl0p Ransomware Group Claims Data Theft from Nearly 50 Companies The Cl0p hacking group has claimed to have stolen significant data from nearly 50 companies, including Shell, Philips, General Electric (GE), and Fiserv. The group reported stealing approximately 89GB from Shell and 13.5GB from Philips, including sensitive engineering documents and project plans. The attacks exploit…
AI-Generated Exploits Target Siemens PLCs in Critical Infrastructure On August 19, 2026, U.S. agencies issued a joint advisory confirming that threat actors are using AI-generated exploitation scripts to target Siemens S7 Series PLCs across critical infrastructure sectors, including water, energy, and manufacturing. The advisory, co-signed by the NSA, CISA, FBI, DOE, and EPA…