Oracle PeopleSoft PeopleTools zero-day RCE (CVE-2026-35273)
Vulnerability
Summary
Hide ▲
Show ▼
Oracle PeopleSoft PeopleTools CVE-2026-35273 is a critical zero-day RCE affecting PeopleSoft Enterprise PeopleTools 8.61 and 8.62. Oracle released emergency mitigations, and the flaw was later confirmed as actively exploited in ShinyHunters data-theft attacks. Affected organizations include Nissan, which says current and former employee data may have been exposed in the campaign.
Related Happenings
Nissan hit by network compromise
Incident
H score48
First: 29.06.2026 23:40
Last: 29.06.2026 23:40
Sources 1
How related:
Nissan says it is still in the early stages of the investigation and has not yet determined the full impact of the breach, but believes attackers accessed personal information that may include employee contact information, banking information, Social Security numbers, Social Insurance Numbers, National Identification Numbers, financial and tax information, and dependent and beneficiary information.
About this happening:
Nissan disclosed a data breach affecting current and former employees after unauthorized access tied to Oracle PeopleSoft exploitation put personnel records at ris...
Nissan hit by network compromise
IncidentHow related: Nissan says it is still in the early stages of the investigation and has not yet determined the full impact of the breach, but believes attackers accessed personal information that may include employee contact information, banking information, Social Security numbers, Social Insurance Numbers, National Identification Numbers, financial and tax information, and dependent and beneficiary information.
About this happening: Nissan disclosed a data breach affecting current and former employees after unauthorized access tied to Oracle PeopleSoft exploitation put personnel records at ris...
National Association of Insurance Commissioners data leak claims
Data Leak
H score82
First: 29.06.2026 23:30
Last: 29.06.2026 23:30
Sources 1
About this happening:
ShinyHunters' June 25 leak update turned the NAIC intrusion into a public data leak and raised questions about what was actually taken from the insurer regulator. The grou...
National Association of Insurance Commissioners data leak claims
Data LeakAbout this happening: ShinyHunters' June 25 leak update turned the NAIC intrusion into a public data leak and raised questions about what was actually taken from the insurer regulator. The grou...
US National Association of Insurance Commissioners (NAIC) hit by network compromise
Incident
H score80
First: 29.06.2026 13:00
Last: 29.06.2026 13:00
Sources 1
How related:
The US National Association of Insurance Commissioners (NAIC) has suffered a security breach that has exposed US citizens’ credit rating data.
About this happening:
NAIC disclosed a security breach that exposed US citizens’ credit rating data and briefly disrupted operations tied to Oracle PeopleSoft. The breach was detected o...
US National Association of Insurance Commissioners (NAIC) hit by network compromise
IncidentHow related: The US National Association of Insurance Commissioners (NAIC) has suffered a security breach that has exposed US citizens’ credit rating data.
About this happening: NAIC disclosed a security breach that exposed US citizens’ credit rating data and briefly disrupted operations tied to Oracle PeopleSoft. The breach was detected o...
Oracle PeopleSoft broad zero-day exploitation campaign
Exploitation Wave
H score82
First: 29.06.2026 13:00
Last: 29.06.2026 13:00
Sources 1
How related:
The incident was the result of “a broad campaign to exploit a vulnerability in PeopleSoft that was unknown to the developer or software users at the time, which affected multiple organizations,” the NAIC added.
About this happening:
A broad PeopleSoft zero-day exploitation campaign exposed multiple organizations to compromise after attackers abused a previously unknown Oracle PeopleSoft vulnerabilit...
Oracle PeopleSoft broad zero-day exploitation campaign
Exploitation WaveHow related: The incident was the result of “a broad campaign to exploit a vulnerability in PeopleSoft that was unknown to the developer or software users at the time, which affected multiple organizations,” the NAIC added.
About this happening: A broad PeopleSoft zero-day exploitation campaign exposed multiple organizations to compromise after attackers abused a previously unknown Oracle PeopleSoft vulnerabilit...
ShinyHunters Oracle PeopleSoft data theft from 300 instances
Data Leak
H score46
First: 11.06.2026 22:39
Last: 11.06.2026 22:39
Sources 1
How related:
Using this flaw, the threat actor allegedly stole data from 300 instances for over 100 organizations.
About this happening:
The ShinyHunters data-leak event against Oracle PeopleSoft instances exposed data from 300 instances across 100+ organizations, expanding the risk of theft-driven...
ShinyHunters Oracle PeopleSoft data theft from 300 instances
Data LeakHow related: Using this flaw, the threat actor allegedly stole data from 300 instances for over 100 organizations.
About this happening: The ShinyHunters data-leak event against Oracle PeopleSoft instances exposed data from 300 instances across 100+ organizations, expanding the risk of theft-driven...
Timeline
-
29.06.2026 23:40 1 articles · 16d ago
Nissan discloses employee data breach tied to Oracle PeopleSoft zero-day
Victim Impact UpdateNissan says it suffered a data breach affecting current and former employees after attackers exploited an Oracle PeopleSoft zero-day associated with CVE-2026-35273. Oracle informed Nissan that personnel records of hundreds of companies may have been obtained and that Nissan was specifically targeted, with potentially exposed data including contact details, banking information, Social Security numbers, Social Insurance Numbers, National Identification Numbers, financial and tax information, and dependent and beneficiary data for employees in the United States, Canada, Mexico, and Brazil.
Show sources
- Nissan discloses employee data breach linked to Oracle zero-day attacks — www.bleepingcomputer.com — 29.06.2026 23:40
-
11.06.2026 22:39 3 articles · 1mo ago
ShinyHunters targets Oracle PeopleSoft in data theft attacks
Exploitation ObservedShinyHunters targeted Oracle PeopleSoft instances in a wave of data theft attacks and claimed to use a gadget chain of old and zero-day flaws to breach PeopleSoft systems. The attacks were said to affect 300 instances across more than 100 organizations, and ransom notes were reportedly left on compromised systems.
Show sources
- Oracle mitigates PeopleSoft zero-day exploited in data theft attacks — www.bleepingcomputer.com — 11.06.2026 22:39
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities — thehackernews.com — 11.06.2026 23:29
- US Federal Insurance Regulator Confirms Data Breach Via Oracle Flaw — www.infosecurity-magazine.com — 29.06.2026 13:00
-
11.06.2026 22:39 2 articles · 1mo ago
Oracle issues emergency mitigations for CVE-2026-35273 in PeopleSoft PeopleTools
Initial DisclosureOracle issued a Security Alert for CVE-2026-35273 in Oracle PeopleSoft PeopleTools, a critical zero-day with CVSS 9.8 that is remotely exploitable without authentication and can lead to remote code execution. Oracle confirmed affected PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62, released emergency mitigations, and said a patch is coming soon.
Show sources
- Oracle mitigates PeopleSoft zero-day exploited in data theft attacks — www.bleepingcomputer.com — 11.06.2026 22:39
- Oracle mitigates PeopleSoft zero-day exploited in data theft attacks — www.bleepingcomputer.com — 11.06.2026 22:39