Oracle PeopleSoft Zero-Day Exposes 100+ Companies
ShinyHunters exploited CVSS 9.8 vulnerability in PeopleTools 8.61 and 8.62 to steal student records from universities The ShinyHunters cybercrime group weaponized CVE-2026-35273 to breach PeopleSoft servers across mostly U.S. organizations, with roughly two-thirds targeting universities according to

Brief summary
What this story is about
ShinyHunters exploited CVSS 9.8 vulnerability in PeopleTools 8.61 and 8.62 to steal student records from universities The ShinyHunters cybercrime group weaponized CVE-2026-35273 to breach PeopleSoft servers across mostly U.S. organizations, with roughly two-thirds targeting universities according to
Why it matters
Reader takeaways
- Prioritize whether the item affects internet-facing systems, databases, middleware, or identity infrastructure.
- Map the source item to your next patch window and document owners before remediation starts.
- Keep the original advisory link because patch details can change after publication.
SEO context
Topic and keyword map
This brief is filed under Oracle security alerts and Critical Patch Update watch.
internet securityOracle Critical Patch UpdateOracle security alertsOracle CVEDBA patchingsecurity advisories