Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223832 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-35273KEVEXPLOITEDPATCHED
oracle · peoplesoft_enterprise_peopletools

CVE-2026-35273: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Mana

Description

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Affected Products

VendorProductVersions
oraclepeoplesoft_enterprise_peopletools8.61, 8.62

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
oraclepeoplesoftcert_advisory90%

References

  • https://www.oracle.com/security-alerts/alert-cve-2026-35273.html(vendor-advisory)

Related News (34 articles)

Tier D
BleepingComputer1d ago
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
→ No new info (linked only)
Tier D
The Hacker News1d ago
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
→ No new info (linked only)
Tier D
SecurityWeek4d ago
ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report
→ No new info (linked only)
Tier D
The Hacker News4d ago
ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
→ No new info (linked only)
Tier C
Rapid7 Blog67d ago
What’s New in Rapid7 Products and Services: Q2 2026 in Review
→ No new info (linked only)
Tier D
Infosecurity Magazine89d ago
Nissan Discloses Employee Data Breach Linked to Oracle Zero-Day
→ No new info (linked only)
Tier D
SecurityWeek89d ago
Nissan Employee Data Breached in Oracle PeopleSoft Hack
→ No new info (linked only)
Tier D
BleepingComputer90d ago
Nissan discloses employee data breach linked to Oracle zero-day attacks
→ No new info (linked only)
Tier D
BleepingComputer90d ago
NAIC says public data stolen in ShinyHunters' PeopleSoft breach
→ No new info (linked only)
Tier D
BleepingComputer90d ago
Hackers now exploit critical Oracle E-Business flaw in attacks
→ No new info (linked only)
Tier D
SecurityWeek90d ago
Insurance Regulators Group NAIC Hit in Oracle PeopleSoft Hack
→ No new info (linked only)
Tier D
CSO Online101d ago
Oracle releases 245 new security patches, all rated ‘high-priority security’
→ No new info (linked only)
Tier D
SecurityWeek102d ago
Oracle’s Second Monthly Security Updates Deliver 245 Patches 
→ No new info (linked only)
Tier D
Heise Security102d ago
Critical Security Patch Update: Oracle veröffentlicht 245 Sicherheitsupdates
→ No new info (linked only)
Tier E
Reddit r/cybersecurity103d ago
Council of Europe hacked
→ No new info (linked only)
Tier D
The Hacker News104d ago
⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More
→ No new info (linked only)
Tier D
Heise Security104d ago
Cybergang ShinyHunters attackiert Oracle-PeopleSoft-Schwachstelle
→ No new info (linked only)
Tier B
CERT-FR105d ago
Bulletin d'actualité CERTFR-2026-ACT-026 (15 juin 2026)
→ No new info (linked only)
Tier D
Help Net Security105d ago
Week in review: Exploited Check Point VPN zero-day, Oracle PeopleSoft servers under attack
→ No new info (linked only)
Tier D
Ars Technica Security107d ago
PeopleSoft 0-day affecting hundreds of organizations steals gigabytes of data
→ No new info (linked only)
Tier C
Rapid7 Blog107d ago
Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)
→ No new info (linked only)
Tier D
CSO Online107d ago
Oracle PeopleSoft zero‑day fuels ShinyHunters extortion spree
→ No new info (linked only)
Tier D
SecurityWeek107d ago
Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters
→ No new info (linked only)
Tier E
Hacker News108d ago
ShinyHunters hacked 100 orgs by exploiting an Oracle PeopleSoft 0-day
→ No new info (linked only)
Tier B
CERT-FR108d ago
Vulnérabilité dans Oracle PeopleSoft (12 juin 2026)
→ No new info (linked only)
Tier D
The Hacker News108d ago
ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities
→ No new info (linked only)
Tier D
BleepingComputer108d ago
Oracle mitigates PeopleSoft zero-day exploited in data theft attacks
→ No new info (linked only)
Tier C
Mandiant Blog108d ago
ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit
→ No new info (linked only)
Tier D
SecurityWeek108d ago
Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks
→ No new info (linked only)
Tier B
CCCS Canada108d ago
Oracle security advisory (AV26-587)
→ No new info (linked only)
Tier D
Help Net Security108d ago
Oracle PeopleSoft servers under attack, Oracle pushes out-of-band security alert
→ No new info (linked only)
Tier B
BSI Advisories108d ago
[NEU] [hoch] Oracle PeopleSoft: Schwachstelle ermöglicht nicht spezifizierten Angriff
→ No new info (linked only)
Tier D
Heise Security108d ago
Oracle warnt außer der Reihe vor kritischer PeopleSoft-Codeschmuggel-Lücke
→ No new info (linked only)
Tier C
VulDB108d ago
CVE-2026-35273 | Oracle PeopleSoft Enterprise PeopleTools 8.61/8.62 Updates Environment Management Remote Code Execution
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
https://www.oracle.com/security-alerts/alert-cve-2026-35273.html
PublishedJun 11, 2026
Last enriched89d agov19
Tags
criticalremote code executionzero-dayextortiondata breachdata leakserver-side request forgeryransomwareinsurancedata theftpublic data theftemployee dataidentity theft
Trending Score144🔥
Source articles34
Independent16
Info Completeness12/14
Missing: epss, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-47057
CVE-2026-47057: Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491,
Trending: 39
HIGHCVE-2026-47063
CVE-2026-47063: Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Trending: 39
MEDIUMCVE-2026-60147
CVE-2026-60147: Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Trending: 36
MEDIUMCVE-2026-47021
CVE-2026-47021: Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Trending: 36
HIGHCVE-2026-47058
CVE-2026-47058: Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491,
Trending: 36

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 11, 2026
Added to CISA KEV
Jun 11, 2026
Discovered by ZDM
Jun 11, 2026
Updated: description
Jun 11, 2026
Updated: tags
Jun 11, 2026
Updated: affectedVersions, exploitAvailable, activelyExploited
Jun 11, 2026
Updated: description, iocs, tags
Jun 11, 2026
Updated: description
Jun 11, 2026
Updated: iocs
Jun 11, 2026
Updated: iocs
Jun 11, 2026
Updated: description, cweIds, tags
Jun 11, 2026
Updated: description, tags
Jun 12, 2026
Updated: description, iocs
Jun 12, 2026
Updated: description, cweIds, iocs, tags
Jun 12, 2026
Updated: tags
Jun 12, 2026
Updated: description
Jun 15, 2026
Updated: description, tags
Jun 29, 2026
Updated: description
Jun 29, 2026
Updated: description, tags
Jun 29, 2026
Updated: description, cweIds, tags
Jun 29, 2026
Updated: description
Jun 30, 2026
Actively Exploited
Aug 4, 2026
Exploit Available
Aug 4, 2026
Patch Available
Aug 4, 2026

Version History

v19
Last enriched 89d ago
v19Tier D89d ago

Updated description with detailed information about the data breach and added a new IOC.

description
via Infosecurity Magazine
v18Tier D90d ago

Updated description with details on the Nissan data breach and added new CWE and tags related to the incident.

descriptioncweIdstags
via BleepingComputer
v17Tier D90d ago

Updated description with details from NAIC regarding the nature of the data stolen and added new tags related to the incident.

descriptiontags
via BleepingComputer
v16Tier D90d ago

Updated description to include details about unauthenticated remote code execution and confirmed active exploitation in ShinyHunter attacks.

description
via BleepingComputer
v15Tier D90d ago

Added substantial new details about the NAIC being targeted and updated IoCs and tags.

descriptiontags
via SecurityWeek
v14Tier D104d ago

Added detailed description of the ShinyHunters group's exploitation tactics and included new IoCs related to the attacks.

description
via Heise Security
v13Tier D107d ago

Updated description with details on exploitation by the ShinyHunters group, added new IoCs, and included new tags related to ransomware and extortion.

tags
via Ars Technica Security
v12Tier C107d ago

Added CWE-918 for server-side request forgery, updated description with new technical details, and included new IoCs and tags.

descriptioncweIdsiocstags
via Rapid7 Blog
v11Tier D107d ago

Updated description with detailed exploitation methods and added a new IOC for the command and control server.

descriptioniocs
via CSO Online
v10Tier D107d ago

Updated description with detailed exploitation information, noted that patches do not appear to be available, and added new IoCs and tags related to the exploitation.

descriptiontags
via SecurityWeek
v9Tier D108d ago

Updated description with details about the ShinyHunters extortion campaign and added new CWE and tags.

descriptioncweIdstags
via The Hacker News
v8Tier D108d ago

Updated description with details on unauthenticated remote code execution and added new IoCs and a new tag for zero-day.

iocs
via BleepingComputer
v7Tier C108d ago

Updated description with detailed technical information about the exploitation campaign and added new IoCs including five IP addresses and a domain.

iocs
via Mandiant Blog
v6Tier B108d ago

Updated description with new details about exploitation in the wild and clarified that no patch is available.

description
via CCCS Canada
v5Tier D108d ago

Updated description with details on mitigations and zero-day attacks, and added new IOC and tags related to the ShinyHunters group.

descriptioniocstags
via SecurityWeek
v4Tier D108d ago

Updated exploit status to actively exploited and added information about potentially affected earlier versions.

affectedVersionsexploitAvailableactivelyExploited
via Help Net Security
v3Tier D108d ago

Marked exploit as available and actively exploited, and added new tags related to the vulnerability.

tags
via Heise Security
v2Tier C108d ago

Updated description with new technical details and clarified that no exploit is available.

description
via VulDB
v1108d ago

Initial creation