CVE-2026-35273

exploited in the wild☆ pin
CVSS
9.8
Reports
16
First seen
Jun 11, 2026
Last seen
Jul 16, 2026
Affected product

Oracle PeopleSoft

Associated actors

Recent reports

High

ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories

The Hacker News
Critical

Over 900 Oracle E-Business Suite instances exposed to ongoing CVE-2026-46817 attacks

Bleeping Computer
Critical

Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild

The Hacker News
High

Nissan data breach linked to Oracle PeopleSoft zero-day exploited by ShinyHunters

Bleeping Computer
High

NAIC confirms ShinyHunters stole public data in PeopleSoft zero-day breach

Bleeping Computer
Critical

Hackers now exploit critical Oracle E-Business flaw in attacks

Bleeping Computer
High

Oracle Releases June 2026 Security Updates: 244 Vulnerabilities Patched

NICS Taiwan
Critical

PeopleSoft PeopleTools Pre-Authentication RCE via PSIGW SSRF and XMLDecoder Deserialization

Trend Micro Research
High

Weekly Cybersecurity Recap: Chrome 0-Day, Oracle PeopleSoft Exploit, Supply Chain Attacks

The Hacker News
Critical

Check Point Threat Intelligence Report – 15 June 2026

Check Point Research
Critical

ShinyHunters actively extorting universities after exploiting Oracle PeopleSoft zero-day

CyberScoop
Critical

CISA Adds CVE-2026-35273 Oracle PeopleSoft to Known Exploited Vulnerabilities Catalog

CISA Advisories
Critical

High Threat Security Alert: Remote Code Execution Vulnerability in Oracle PeopleSoft (CVE-2026-35273)

GovCERT.HK
Critical

ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach Universities

The Hacker News
Critical

Oracle patches critical PeopleSoft zero-day exploited by ShinyHunters in data theft attacks

Bleeping Computer
Critical

Oracle PeopleSoft Enterprise PeopleTools Critical Vulnerability (CVE-2026-35273)

Canadian Centre Alerts

This page shows data on a 7-day delay. Free accounts get the full delayed feed; real-time reports, indicators, and the API start at $29/mo.