CRITICALCISA KEVIN THE WILD

CVE-2026-35273

Published: June 11, 2026· Updated: Jun 17, 2026

9.8
CVSS v3.1
EPSS:22.21%probability of exploitation in 30 daysPercentile:95.9th

Official Description

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

NVD Source

Risk Analysis

This critical vulnerability in Oracle PeopleSoft Enterprise PeopleTools allows an unauthenticated attacker with network access via HTTP to fully compromise the system. Successful exploitation can lead to complete takeover of PeopleSoft Enterprise PeopleTools. The CVSS score of 9.8 indicates extreme severity and immediate attention is required.

This vulnerability is actively being exploited in the wild and is listed in CISA's KEV catalog. It is remotely exploitable with low attack complexity by unauthenticated attackers.

Recommended Action

Apply the latest security patches from Oracle for PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62. Restrict network access to PeopleSoft systems to authorized users and networks only.

Generated by the CTIWATCH analysis pipeline from this CVE's metadata (CVSS, EPSS, KEV status, exploit intelligence). Verify against vendor advisories before acting.

Technical Analysis

CVE-2026-35273 can be exploited remotely over the network without requiring physical or adjacent access, significantly expanding the attack surface for threat actors.

The vulnerability requires no privileges and no user interaction, making it a prime target for automated exploitation campaigns and worm-like propagation.

A successful exploit results in complete confidentiality breach (data exposure), full integrity compromise (data manipulation), availability disruption (denial of service), with a CVSS base score of 9.8.

CISA has added CVE-2026-35273 to the Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. U.S. federal agencies are required to patch this within the mandated timeframe, and all organizations should treat remediation as urgent.

CVSS v3.1 Vector Breakdown

Exploitability
Attack VectorNetwork
Attack ComplexityLow
Privileges Req.None
User InteractionNone
ScopeUnchanged
Impact
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Vendors & Products

Oracle1 product(s)
peoplesoft enterprise peopletools
Source: NVD CPE · 2 total CPE entries

Exploit & PoC Resources

ACTIVE EXPLOITATIONConfirmed exploitation in the wild
External links open in a new tab. Always verify in a controlled environment before use.

Official Patches & Advisories

News & Research Mentioning CVE-2026-35273

Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)
Rapid7 Blog· Jun 12, 2026

Overview On June 10, 2026, Oracle published a security alert for CVE-2026-35273, a critical vulnerability in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools. Oracle released an out-of-band patch the same day as the advisory, underscoring the urgency of remediation. The vulnerability has a CVSSv3.1 score of 9.8 and is remotely exploitable without authentication. Per the vendor advisory, successful exploitation may result in remote code execution (RCE). TrendAI has classified the underlying flaw as a server-side request forgery (CWE-918). PeopleTools versions 8.61 and 8.62 are affected. CVE-2026-35273 was reported to Oracle through TrendAI's Zero Day Initiative. According to a report published by Mandiant on June 11, 2026, this vulnerability has been exploited in the wild as a zero-day prior to the vendor security alert, with active exploitation observed between May 27 and June 9, 2026, predating Oracle's advisory by two weeks. The vulnerability was adde

CISA Adds One Known Exploited Vulnerability to Catalog
CISA Alerts· Jun 12, 2026

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-35273 Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies, updating BOD 22-01. BOD 26-04 reinforces the importance of the KEV catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically tho [xlite_meta score:48 src:CISA Alerts xlite_fp:5a46b7e568b3f85ac4620f992424f0be2316f249c7f6c7bf2539638b45060663]

Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters
SecurityWeek· Jun 12, 2026

Oracle has mitigated CVE-2026-35273, but it has not publicly confirmed the vulnerability’s in-the-wild exploitation. The post Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters appeared first on SecurityWeek. [xlite_meta score:56 src:SecurityWeek xlite_fp:f413d42f81b403721b8ee05730403ed33c325916d3b55002dbe7f1d557ad76ce]

ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities
The Hacker News· Jun 11, 2026

The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private. The campaign hit universities hardest. Google's Mandiant attributes it to the group it tracks as UNC6240, and dates the activity between May 27 and June 9. Oracle did not publish its advisory until June 10, so the bug was a [xlite_meta score:56 src:The Hacker News xlite_fp:968b5598cbf048a4b2d1debfd9c31c9e1f2281ba0abbd9f9207b14505b1e5873]

Oracle mitigates PeopleSoft zero-day exploited in data theft attacks
BleepingComputer· Jun 11, 2026

Oracle is warning about a critical PeopleSoft Suite zero-day vulnerability tracked as CVE-2026-35273 that allows unauthenticated remote code execution, with the flaw actively exploited in ShinyHunter data theft attacks. [...] [xlite_meta score:70 src:BleepingComputer xlite_fp:24410115fcfb868a57cd6d21a3fcfac16d601dd8af8457e6dbff6c58cbc83407]

ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit
Mandiant Blog· Jun 11, 2026

Introduction Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure. The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of CVE-2026-35273, a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component. The exploitation of this vulnerability directly aligns with the observed targeting of Environment Management Hub (PSEMHUB) endpoints. Because this activity predates Oracle's June 10, 2026 advisory, the vulnerability was exploited as a zero-day. Upon becoming aware of active scanning and exploitation, we initiated notifications to over 100 global organizations whose IP addresses correlated with potentially vulnerable endpoints. Most of these organizations were based in the United States, and 68 percent operated within the higher education sector. Subseq

Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks
SecurityWeek· Jun 11, 2026

Oracle has released mitigations for CVE-2026-35273, but it has not said whether it’s a zero-day exploited in ShinyHunters attacks. The post Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks appeared first on SecurityWeek. [xlite_meta score:56 src:SecurityWeek xlite_fp:6607f8985e3bc881c0061d636fe763c8c9dbc9a28c62b5c5a446e604aa77fe75]

All References (2)

Quick Facts

CVE IDCVE-2026-35273
CVSS Score9.8 / 10
SeverityCRITICAL
CISA KEVYES — Active Exploitation
ExploitIN THE WILD
EPSS (30d)22.21%
Affected1 vendor(s)
PublishedJun 11, 2026

Known Threat Actors

ShinyHunters
financial
hunters
financial
shinyhunters
financial

Organizations Hit via This CVE147

+135 more organizations

Recommended Actions

  • Apply vendor patches immediately
  • Monitor CVE-2026-35273 in threat intel feeds
  • Review IDS/IPS signatures for exploitation attempts
  • !CISA KEV: Federal agencies must patch per BOD 22-01 timeline
  • !Active exploitation confirmed — treat as P1
Data sourced from NVD (NIST), CISA KEV, and EPSS (FIRST). Analysis generated by CTIWatch. CVE data is provided under the NVD usage policy.