Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1451+ Articles
151+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. Security
  3. CVE-2026-35273: Critical Oracle PeopleSoft RCE Exploited in the Wild
CVE-2026-35273: Critical Oracle PeopleSoft RCE Exploited in the Wild

Critical Security Alert

This vulnerability is actively being exploited. Immediate action is recommended.

SECURITYCRITICALCVE-2026-35273

CVE-2026-35273: Critical Oracle PeopleSoft RCE Exploited in the Wild

A CVSS 9.8 unauthenticated remote code execution flaw in Oracle PeopleSoft Enterprise PeopleTools 8.61 and 8.62 is being actively exploited, with threat...

Dylan H.

Security Team

June 11, 2026
2 min read

Affected Products

  • Oracle PeopleSoft Enterprise PeopleTools 8.61
  • Oracle PeopleSoft Enterprise PeopleTools 8.62

Overview

CVE-2026-35273 is a critical unauthenticated remote code execution vulnerability in Oracle PeopleSoft Enterprise PeopleTools, scoring CVSS 9.8. The flaw exists in the Updates Environment Management component and affects PeopleTools versions 8.61 and 8.62. An unauthenticated attacker with network access via HTTP can fully compromise a PeopleSoft instance with no credentials required.

The vulnerability was disclosed by Oracle and has been actively exploited by threat groups including ShinHunters, who leveraged it in attacks against university and enterprise targets — most notably a breach at the University of Nottingham that exposed data of over 450,000 students.

Technical Details

The vulnerability allows:

  • Unauthenticated access — no credentials required
  • Remote code execution via HTTP requests to the Updates Environment Management component
  • Full system compromise once exploited — attackers can pivot to connected databases and enterprise systems

The flaw is classified as "easily exploitable" in Oracle's advisory, meaning automated exploitation tooling is likely in circulation.

Affected Versions

ProductVersions Affected
Oracle PeopleSoft Enterprise PeopleTools8.61, 8.62

Versions outside this range are not listed as affected, but organizations should verify their specific patch levels.

Active Exploitation

This CVE has been confirmed as actively exploited in the wild. The threat actor group ShinHunters was observed using this vulnerability to breach Nottingham University, resulting in the exposure of records for over 450,000 students. Oracle issued emergency patches following disclosure.

CISA is expected to add this CVE to the Known Exploited Vulnerabilities (KEV) catalog given confirmed in-the-wild usage.

Remediation

  1. Apply Oracle's critical patch immediately — Oracle released an out-of-band patch upon disclosure
  2. Restrict network access to PeopleSoft Updates Environment Management endpoints at the perimeter
  3. Review access logs for anomalous HTTP requests to the affected component going back at least 30 days
  4. Rotate credentials for all accounts with access to PeopleSoft and connected systems
  5. Audit connected databases for signs of lateral movement or data exfiltration

References

  • NVD Detail: CVE-2026-35273
  • Oracle Critical Patch Update Advisory — June 2026
  • Nottingham University breach coverage — related slug: shinyhunters-exploits-oracle-peoplesoft-zero-day-cve-2026-35273-to-breach-univer
#Oracle#PeopleSoft#RCE#Zero-Day#Active Exploitation#Enterprise

Related Articles

CVE-2024-21182: Oracle WebLogic Server Unspecified Vulnerability

Oracle WebLogic Server contains an unspecified vulnerability allowing unauthenticated attackers network access via T3 and IIOP protocols, potentially exposing…

5 min read

CVE-2025-53521: F5 BIG-IP APM Remote Code Execution — CISA

A critical unauthenticated RCE vulnerability in F5 BIG-IP APM is being actively exploited in the wild. Malicious traffic targeting access policy virtual...

4 min read

CVE-2026-21992: Critical Oracle Identity Manager

Oracle's March 2026 Critical Patch Update includes CVE-2026-21992, a CVSS 9.8 unauthenticated remote code execution vulnerability in Oracle Identity...

7 min read
Back to all Security Alerts