CVE
CVE-2026-35273
- First Reported
- Sep 26, 2026
- Latest Reported
- Sep 28, 2026
Reported Context (2)
- it gained access to the FBI site and other victims by exploiting a recently patched vulnerability (CVE-2026-35273) in PeopleSoft, a software-as-a-service platform from the software giant Oracle that is broadly used Dutch Police Arrest Former Hacker in ShinyHunters Investigation
- Mandiant and GTIG report renewed mass exploitation of CVE-2026-35273 in Oracle PeopleSoft by UNC6240 (ShinyHunters), using a URL-encoded WAF bypass to reach the vulnerable PSEMHUB endpoint and deploy web shells ShinyHunters Resume Mass Exploitation of Oracle PeopleSoft Vulnerability CVE-2026-35273
Malware (1)
Threat Actors (11)
MITRE ATT&CK (13)
Vendors (3)
Products (3)
Tools (4)
Industries (7)
Countries (4)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.