Vulnerabilities & Exploits · Web App Attack

FBI Breach Followed a Missed PeopleSoft Patch

Reuters reported the FBI removed an Accenture contractor after a missed Oracle PeopleSoft security patch let ShinyHunters steal personal details from thousands of FBI employees. The flaw at issue is CVE-2026-35273.

Google-owned Mandiant says the group also used URL encoding to disguise the request well enough that a web application firewall rule did not recognize the blocked PeopleSoft Environment Management Hub endpoint, yet the request still reached it. In plain terms, the patch was skipped and the perimeter control was written narrowly enough to be walked around.

For organizations that let a contractor or MSP run internet-facing PeopleSoft, the exposure sits in the maintenance chain as much as in the software. If a managed platform misses an issued patch, a WAF rule can still leave employee-data systems reachable through a differently written URL.

2 sources · 8h ago

CVE-2026-35273

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Known ransomware campaign use. EPSS 9% (95th percentile).

CISA federal remediation date Jun 15 · date passed

Timeline

Sources

Part of the PlainSec briefing for 2026-10-06

Every edition of this story: FBI Breach Followed a Missed PeopleSoft Patch

More from today