AI Stories on SHORT INFO are generated & curated with AI
unverified 21 Jun, 13:10

Oracle PeopleSoft zero-day CVE-2026-35273 exploited by ShinyHunters hits universities

Students and staff at more than 100 organizations, most of them US universities, had personal data stolen through a critical flaw in Oracle $ORCL PeopleSoft. The extortion group ShinyHunters exploited the bug before a patch existed. CISA lists CVE-2026-35273 as actively exploited

Personal records belonging to students and staff at more than 100 organizations have been exposed through a critical flaw in Oracle PeopleSoft, the enterprise software many universities rely on for human resources, payroll and student administration. The vulnerability, tracked as CVE-2026-35273, sits in the PeopleTools environment management component and lets an attacker run code on a server with no login, earning a near-maximum severity score of 9.8 out of 10. According to CISA and security firms including Rapid7, the extortion group known as ShinyHunters exploited the bug as a zero-day, meaning it was used in real attacks before Oracle had a fix available. The campaign concentrated on higher education, with roughly two thirds of confirmed victims being academic institutions in the United States. Attackers used the access to copy sensitive data and then pressure organizations for payment. Oracle issued an out-of-band security alert and is urging administrators to patch PeopleTools versions 8.61 and 8.62 without delay. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on June 12, which obliges federal agencies to remediate quickly. For anyone whose university or employer runs PeopleSoft, the practical risk is that names, contact details and other personal information may already be in criminal hands. Oracle trades under the ticker $ORCL. Source: CISA, Rapid7, The Hacker News.

Published on
ThreadsBlueskyFacebookX