Oracle has issued an emergency mitigation for CVE-2026-35273, a critical zero-day vulnerability in PeopleSoft PeopleTools (versions 8.61 and 8.62) with a CVSS score of 9.8 that enables unauthenticated remote code execution. The flaw is being actively exploited by the ShinyHunters extortion gang, who have reportedly breached over 300 PeopleSoft instances across more than 100 organizations to steal data and demand ransoms. Mandiant CTO Charles Carmakal confirmed the active exploitation. ShinyHunters claims to use a 'gadget chain' of old and zero-day vulnerabilities. Administrators are urged to apply Oracle's emergency mitigations and check logs for connections from a set of known attacker IP addresses.

3m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Zero-day exploited in ShinyHunter data theft attacksTest every layer before attackers do
260 Impressions