Dossier
CVE-2026-35273
Coverage of CVE-2026-35273 in the Nexus archive.
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities
ShinyHunters exploited an unpatched Oracle PeopleSoft zero-day (CVE-2026-35273) to breach enterprise systems, targeting universities most severely. Google's Mandiant linked the attacks to UNC6240, with activity occurring between May 27 and June 9, just one day before Oracle released its security advisory on June 10.
- Oracle mitigates PeopleSoft zero-day exploited in data theft attacks
Oracle is addressing a critical zero-day vulnerability in PeopleSoft Suite, tracked as CVE-2026-35273, which enables unauthenticated remote code execution and is being actively exploited in ShinyHunter data theft attacks.