Skip to content
ShinyHunters Escalate Oracle PeopleSoft Exploitation Amid Microsoft Mega-Patch

ShinyHunters Escalate Oracle PeopleSoft Exploitation Amid Microsoft Mega-Patch

First seen 29 Sep 2026, 07:17 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 08:10 UTC

ShinyHunters, a hacking group, has escalated attacks exploiting Oracle PeopleSoft vulnerability CVE-2026-35273 following the arrest of a member in the Netherlands. This vulnerability, with a CVSS score of 9.8, is being exploited using URL-encoding techniques to bypass web application firewalls. Microsoft recently released its largest patch batch ever, addressing 974 vulnerabilities, including CVE-2026-69730 and CVE-2026-85880. Apple also patched a zero-day vulnerability in CoreGraphics, CVE-2026-86950, which may have been exploited in targeted attacks. The ongoing exploitation of Oracle PeopleSoft affects multiple sectors globally, with ShinyHunters deploying web shells to gain unauthorized access. Security experts are urging organizations to prioritize patching CVE-2026-35273 and monitor for indicators of compromise. The situation remains critical as the threat landscape evolves rapidly.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-11
CVE-2026-35273 published
Oracle disclosed a critical vulnerability in PeopleSoft with a CVSS score of 9.8.
Defendwork
2026-09-05
CVE-2026-86060 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-08
Microsoft's 974 CVEs patch released
Microsoft published its largest security update to address 974 vulnerabilities across its products.
Defendwork
2026-09-08
CVE-2026-85880 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-08
CVE-2026-81963 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-08
CVE-2026-69730 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-08
CVE-2026-69829 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88771 added to CISA KEV
CISA confirmed active exploitation of CVE-2026-88771 in the wild.
Defendwork
2026-09-27
CVE-2026-88772 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-28
CVE-2026-86950 published
Apple released updates for a CoreGraphics zero-day vulnerability affecting iOS and macOS.
Defendwork

More articles in this cluster (3)

Following this threat?

Track Jadepuffer, ShinyHunters and Lunex Stealer in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed