Skip to content

CVE-2026-20245

CVE

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
June 8, 2026
Last Seen
June 11, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft has been exploited by the ShinyHunters group, leading to breaches of over 100 organizations, primarily in the education sector. The vulnerability allows unauthenticated remote code execution, enabling attackers to compromise sys...

RubyGems has introduced dependency cooldowns in Bundler to mitigate supply chain attacks that exploit newly published packages. This feature delays the installation of packages until they have been available for a specified number of days, allowing time for malicious versions to be identified and re...

Public Exploits

Checking GitHub for proof-of-concept code…