Oracle PeopleSoft PeopleTools zero-day CVE-2026-35273 unauthenticated RCE exploited by ShinyHunters, University of Nottingham first confirmed victim
Any organization on Oracle $ORCL PeopleSoft PeopleTools 8.61 or 8.62 can be taken over remotely with no login. CVE-2026-35273 was exploited as a zero-day from May 27 to June 9 by ShinyHunters in data theft attacks on universities. The University of Nottingham is the first confirm
A critical flaw in Oracle's PeopleSoft PeopleTools software left organizations exposed to remote takeover with no login required, and attackers were already inside before the vendor said a word. Oracle ($ORCL) has issued out-of-band mitigations for CVE-2026-35273, which affects PeopleTools versions 8.61 and 8.62. Researchers classify it as a server-side request forgery weakness that needs only network access over HTTP to seize control of a server. What makes this case serious is the timeline. According to reporting from Rapid7, Help Net Security and The Hacker News, the vulnerability was exploited in the wild as a zero-day between May 27 and June 9, roughly two weeks before Oracle published its advisory. The data theft group known as ShinyHunters has been linked to the attacks, with a focus on the education sector. The University of Nottingham in the UK is the first publicly confirmed victim, and Google's threat researchers have corroborated the exploitation. PeopleSoft runs core human resources, payroll and student record systems at universities, government bodies and large employers, which is exactly the kind of sensitive personal data ShinyHunters monetizes. The same group has reportedly compromised more than 100 organizations by chaining Oracle vulnerabilities. Oracle says a full patch is on the way, but with active exploitation confirmed, the mitigations are the only line of defense available to administrators right now.