What it is
CVE-2026-35273 is an unauthenticated vulnerability affecting Oracle PeopleSoft Enterprise PeopleTools. Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates...
Vulnerability report
PeopleSoft Enterprise PeopleTools
Oracle / PeopleSoft Enterprise PeopleTools · 8.61
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2026-35273 is an unauthenticated vulnerability affecting Oracle PeopleSoft Enterprise PeopleTools. Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates...
Is it exploited?
Yes. Previdian sensors observed exploitation attempts with confirmed confidence. Listed in CISA KEV. Also confirmed by third-party sources.
Who is affected?
Oracle / PeopleSoft Enterprise PeopleTools 8.61.
What should we do?
Patch immediately, validate internet-facing exposure, and monitor for matching requests.
Overview
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.
Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Analyst-curated context on exploitation evidence and operational relevance.
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
BleepingComputer
A trusted third party reported exploitation.
Previdian sensor
Previdian first observed exploitation attempts targeting this vulnerability in our honeypot sensors.
BleepingComputer
Malware families have been linked to exploitation of this CVE.
GitHub
Public scanner or PoC coverage increases practical exploitability.
Per-source evidence links for KEV attestations are available through the Previdian Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| BleepingComputer First | 2026-06-11 20:20 UTC |
| CISA | 2026-06-12 00:00 UTC |
| Rapid7 | 2026-06-12 14:20 UTC |
| CVE | 2026-06-12 18:01 UTC |
| All CISA Advisories | 2026-06-12 18:20 UTC |
| Previdian Sensors | 2026-06-14 13:47 UTC |
| Tenable Blog | 2026-06-18 10:20 UTC |
| The Shadowserver | 2026-07-10 00:00 UTC |
Operational indicators for this CVE are listed under Detection.
Sensor telemetry
Previdian sensors recorded exploitation attempts targeting this vulnerability. The cards and chart show volume, unique attackers, and daily activity.
578
Attempts observed
60
Unique attacker IPs
23
Attacker countries
AU · BG · BY · CH · CN · CY · DE · DK · FR · HK · ID · IN · JP · KE · LT · MY · NL · PK · RU · SC · SG · US · VN
15
Sensors observed
CVE-2026-35273 exploitation attempts over the last 89 days
Daily events observed by Previdian sensors
Updated 09 Oct 2026
First observed 14 Jun 2026 · Last observed 08 Oct 2026
Pro adds sensor region and window summaries. Enterprise adds raw IPs, paths, User-Agents, and payloads.
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Request targets and User-Agents available in Pro. Callback host details available in Enterprise.
Nuclei template detected 19 Jun 2026.
View Nuclei template (opens in new tab)Previdian virtual patch guidance is available for this CVE.
Attacker IP indicators observed · available in Pro and Enterprise.
Sensor-derived attacker IP indicators are available to Pro and Enterprise accounts under Detection and through the Pro API.
Learn about Pro API accessScanner and exploit-framework references linked to this CVE.
| Scanner | Reference | Detected |
|---|---|---|
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-35273.yaml | 19 Jun 2026 |
Compensating WAF rules for this CVE.
Enterprise feature. Virtual patch rule content and deployable vendor exports (ModSecurity, Cloudflare, AWS WAF) are available to Previdian Enterprise users.
Risk and context
CVSS v3.1
Potential damage if exploited. Separate from whether attackers are using it.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
9.4%
Estimated chance of exploitation in the next 30 days. Previdian's warning comes from evidence, not this score.
Recent mention · The Hacker News
Ravie LakshmananOct 06, 2026 The U.S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor for their alleged role in a ShinyHunters-breach that led to the theft of personal details of thousands of bureau employees. That's according to a report from...
Read full advisoryRecent mention · The Hacker News
FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters BreachThe Hacker News · 06 Oct 2026
Ravie LakshmananOct 06, 2026 The U.S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor for their alleged role in a ShinyHunters-breach that led to the theft of personal details of thousands of bureau employees. That's according to a report from Reuters, citing two sources familiar with the matter. "To date, our review has determined that the incident occurred as the result of a security failure of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the platform," Brett Leatherman,...
Recent mention · The Hacker News
Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters InvestigationThe Hacker News · 29 Sep 2026
Ravie LakshmananSep 29, 2026United States Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group. "It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters," the Politie Landelijke Opsporing en Interventies said in an X post Monday. Police said the individual is expected to appear before the Rotterdam District Court on September 29, 2026. Although law enforcement officials did not disclose any additional details, independent security journalist...
Recent mention · The Record
ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warnsThe Record · 28 Sep 2026
A vulnerability in a popular line of products from Oracle is being used in a new campaign by the prolific ShinyHunters hacking group, which recently claimed credit for an attack on the FBI’s jobs site.
Recent mention · CyberInsider
Google warns ShinyHunters is mass-exploiting Oracle PeopleSoft flawCyberInsider · 26 Sep 2026
Google’s Mandiant and Threat Intelligence Group (GTIG) have observed ShinyHunters launching a renewed mass-exploitation campaign against vulnerable Oracle PeopleSoft servers, compromising dozens of systems across multiple industries. The activity supports recent claims from the cybercrime group that it had resumed exploiting PeopleSoft environments against a broader range of targets. The threat group, tracked by Google … The post Google warns ShinyHunters is mass-exploiting Oracle PeopleSoft flaw appeared first on CyberInsider.
Recent mention · The Hacker News
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web ShellsThe Hacker News · 26 Sep 2026
Ravie LakshmananSep 26, 2026Vulnerability / Web Security Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution. The vulnerability was first exploited as a zero-day in attacks against academic institutions to conduct reconnaissance, deploy remote access software like MeshCentral agent for persistence, move...
Recent mention · Google Threat Intelligence
Introduction As an update to the June 2026 post, ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit, Mandiant and Google Threat...Google Threat Intelligence · 25 Sep 2026
Introduction As an update to the June 2026 post, ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit, Mandiant and Google Threat Intelligence Group (GTIG) have identified renewed mass exploitation of CVE-2026-35273 by UNC6240 (ShinyHunters), along with expanded global targeting across multiple sectors. In June, the threat actor exploited this vulnerability as a zero-day predominantly against academic institutions. This new wave of activity stems from UNC6240 modifying its exploit to bypass web application firewall (WAF) rules blocking the vulnerable Environment Management...
Recent mention · SOCRadar
ShinyHunters Claims Access to FBI SystemsSOCRadar · 24 Sep 2026
ShinyHunters Claims Access to FBI Systems Days after hijacking Clop's Dark Web leak site, ShinyHunters claims it breached the FBI, defaced part of its recruitment website, and stole sensitive information belonging to emp
Recent mention · Security Affairs
ShinyHunters claims FBI breach after alleged PeopleSoft zero-day attackSecurity Affairs · 23 Sep 2026
ShinyHunters claims FBI breach via PeopleSoft zero-day, steals staff data; FBI investigating, no confirmation yet. The popular cybercrime group ShinyHunters is claiming that it breached the U.S. Federal Bureau of Investigation (FBI) and stole sensitive information belonging to FBI employees and job applicants. The group says the operation was not financially motivated and was instead […]
Recent mention · The Hacker News
ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job ApplicantsThe Hacker News · 23 Sep 2026
Ravie LakshmananSep 23, 2026Data Breach / Cybercrime The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency. "We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job," the group said in a statement posted on their dark web site. "Whether it be a Special Agent or any other role within your agency. The following FBI services were compromised: Criminal Justice...
Recent mention · Zero Day Initiative Published Advisories
ZDI-26-387: Oracle PeopleSoft HttpListeningConnector Server-Side Request Forgery VulnerabilityZero Day Initiative Published Advisories · 24 Jun 2026
This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Oracle PeopleSoft. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.3. The following CVEs are assigned: CVE-2026-35273.
Recent mention · Zero Day Initiative Published Advisories
ZDI-26-388: Oracle PeopleSoft HubMBeanPersistance Deserialization of Untrusted Data Remote Code Execution VulnerabilityZero Day Initiative Published Advisories · 24 Jun 2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle PeopleSoft. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-35273.
Recent mention · Zero Day Initiative Published Advisories
ZDI-26-389: Oracle PeopleSoft ExecuteProcessActivityCommand External Control of File Path Remote Code Execution VulnerabilityZero Day Initiative Published Advisories · 24 Jun 2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle PeopleSoft. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-35273.
Recent mention · Tenable Blog
Oracle June 2026 Critical Security Patch Update Addresses 243 CVEs (CVE-2026-35273)Tenable Blog · 18 Jun 2026
Oracle addresses 243 CVEs in its June 2026 Critical Security Patch Update with 245 patches, including 122 critical updates.Key TakeawaysThe June 2026 Critical Security Patch Update (CSPU) contains fixes for 243 unique CVEs in 245 security updates122 issues (49.8% of all patches) were assigned a critical severity ratingOracle Fusion Middleware received the highest number of patches at 106, accounting for 43.3% of all patchesBackgroundOn June 16, Oracle released its Critical Security Patch Update (CSPU) for June 2026. Beginning in May 2026, Oracle introduced CSPUs as a monthly release cycle...
Recent mention · CyberInsider
Google warns of Oracle PeopleSoft attacks hitting universitiesCyberInsider · 12 Jun 2026
Google's Mandiant and Google Threat Intelligence Group (GTIG) say the ShinyHunters extortion group exploited a critical Oracle PeopleSoft vulnerability as a zero-day to compromise education institutes. The activity, tracked as UNC6240, was observed between May 27 and June 9 and involved exploitation of CVE-2026-35273, a critical remote code execution flaw in the Environment Management component … The post Google warns of Oracle PeopleSoft attacks hitting universities appeared first on CyberInsider.
Recent mention · Rapid7
Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)Rapid7 · 12 Jun 2026
OverviewOn June 10, 2026, Oracle published a security alert for CVE-2026-35273, a critical vulnerability in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools. Oracle released an out-of-band patch the same day as the advisory, underscoring the urgency of remediation. The vulnerability has a CVSSv3.1 score of 9.8 and is remotely exploitable without authentication. Per the vendor advisory, successful exploitation may result in remote code execution (RCE). TrendAI has classified the underlying flaw as a server-side request forgery (CWE-918). PeopleTools versions...
Recent mention · All CISA Advisories
CISA Adds One Known Exploited Vulnerability to CatalogAll CISA Advisories · 12 Jun 2026
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-35273 Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies, updating BOD...
Recent mention · The Hacker News
ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach UniversitiesThe Hacker News · 11 Jun 2026
The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private. The campaign hit universities hardest. Google's Mandiant attributes it to the group it tracks as UNC6240, and dates the activity between May 27 and June 9. Oracle did not publish its advisory until June 10, so the bug was a
Recent mention · DarkWebInformer
Critical Oracle PeopleSoft PeopleTools RCE Exposes Enterprise Systems (CVE-2026-35273)DarkWebInformer · 11 Jun 2026
CVE-2026-35273 is a critical unauthenticated remote code execution vulnerability in Oracle PeopleSoft Enterprise PeopleTools. Rated CVSS 9.8, the flaw affects PeopleTools versions 8.61 and 8.62 and requires immediate mitigation.
Recent mention · BleepingComputer
Oracle mitigates PeopleSoft zero-day exploited in data theft attacksBleepingComputer · 11 Jun 2026
Oracle is warning about a critical PeopleSoft Suite zero-day vulnerability tracked as CVE-2026-35273 that allows unauthenticated remote code execution, with the flaw actively exploited in ShinyHunter data theft attacks. [...]
Recent mention · Google Threat Intelligence
Introduction Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion campaign attributed to UNC6240...Google Threat Intelligence · 11 Jun 2026
Introduction Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure. The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of CVE-2026-35273, a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component. The exploitation of this vulnerability directly aligns with the observed targeting of Environment Management Hub (PSEMHUB) endpoints. Because this activity...
Recent mention · Oracle Security Alerts
Oracle Security Alert Advisory - CVE-2026-35273Oracle Security Alerts · 11 Jun 2026
These PoCs are unverified and could contain malware. Use at your own risk.
nuclei · Created Unknown
Timeline
00:00 UTC
Exploitation attested by an external source
14:21 UTC
Compensating WAF rule available to block exploitation
04:30 UTC
Public proof-of-concept code published
04:30 UTC
Scanner coverage available
10:20 UTC
Exploitation attested by an external source
13:47 UTC
Indicators of compromise recorded
13:47 UTC
Evidence-backed exploitation signal
18:20 UTC
Exploitation attested by an external source
18:01 UTC
Exploitation attested by an external source
14:20 UTC
Exploitation attested by an external source
00:00 UTC
Listed in the CISA Known Exploited Vulnerabilities catalog
00:00 UTC
Exploit observed in malware
20:20 UTC
High-confidence, third-party attested exploitation
02:25 UTC
Vulnerability disclosed publicly
20:03 UTC
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2026-35273
Free JSON includes basic KEV fields{
"cve_id": "CVE-2026-35273",
"confidence": "Confirmed",
"cvss_score": 9.8,
"cvss_estimated": false,
"epss_score": 0.09444,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": true
},
"sensor_telemetry": { "attempts": 578, "sensors": 15 }
}