Skip to content

security_identifier

CVE-2026-35273

A critical unauthenticated remote code execution vulnerability in Oracle PeopleSoft PeopleTools, patched by Oracle in June 2026 and linked to exploitation against education-sector organizations.

Current clusters

security14 publishers

ShinyHunters pins its claimed FBI breach on an unpatched PeopleSoft RCE

The extortion crew defaced apply.fbijobs.gov on September 22 and told reporters it got remote code execution from a new Oracle PeopleSoft flaw, the same one it says it is now using against Fortune 500 targets. No technical details are public.

Perspective Coverage

13 publishers
Builder
Builder 25%
Operator
Operator 48%
Investor
Investor 27%

Reality

Evidence48
Adoption35
Hype gap+34
Incentives78
Confidence62