CVE-2026-35273
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Published Jun 11, 2026
- CVSS 9.8 critical
- 9.4% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
Affected software
In the news
- Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation SecurityWeek ·
- Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation The Hacker News ·
- Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation Krebs on Security ·
- FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day Help Net Security ·
- Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign SecurityWeek ·
- ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks BleepingComputer ·
- Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells The Hacker News ·
- ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft Google Threat Intelligence ·
- ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants The Hacker News ·
- Exploits and vulnerabilities in Q2 2026 Securelist ·