Skip to content

CVE-2026-35273

CVE

Threat entity extracted from intelligence sources

Frequency
26
occurrences
First Seen
June 11, 2026
Last Seen
August 20, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

Chinese hackers infiltrated Microsoft 365 environments, maintaining access for 18 months before detection. The attack exploited vulnerabilities to harvest sensitive data from various organizations. Simultaneously, a new vulnerability in Oracle PeopleSoft (CVE-2026-35273) was disclosed, with active e...

A pre-authentication remote code execution (RCE) vulnerability, CVE-2026-35273, was discovered in Oracle PeopleSoft PeopleTools, affecting versions 8.61 and 8.62. The vulnerability allows unauthenticated attackers to execute code within the application server's Java virtual machine (JVM) by exploiti...

A critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft has been exploited by the ShinyHunters group, leading to breaches of over 100 organizations, primarily in the education sector. The vulnerability allows unauthenticated remote code execution, enabling attackers to compromise sys...

On August 19, 2026, U.S. agencies issued a joint advisory confirming that threat actors are using AI-generated exploitation scripts to target Siemens S7 Series PLCs across critical infrastructure sectors, including water, energy, and manufacturing. The advisory, co-signed by the NSA, CISA, FBI, DOE,...

Public Exploits

Checking GitHub for proof-of-concept code…

Related Articles (25)

1 / 5