
Oracle warns of CVE-2026-35273: ShinyHunters exploited a PeopleSoft zero-day to breach 100+ firms
A 9.8 CVSS PeopleSoft flaw is being used in the wild, unpatched, and exploitable over the internet.
By Lama Al-Rashid·· 3 min
2 briefings · “cve-2026-35273”

A 9.8 CVSS PeopleSoft flaw is being used in the wild, unpatched, and exploitable over the internet.

A PeopleSoft PeopleTools remote takeover via CVE-2026-35273 is being used in the wild, with data theft and extortion claims.