Vulnerabilities & Exploits · Web App Attack
FBI Breach Followed a Missed PeopleSoft Patch Reuters reported the FBI removed an Accenture contractor after a missed Oracle PeopleSoft security patch let ShinyHunters steal personal details from thousands of FBI employees. The flaw at issue is CVE-2026-35273 .
Google-owned Mandiant says the group also used URL encoding to disguise the request well enough that a web application firewall rule did not recognize the blocked PeopleSoft Environment Management Hub endpoint, yet the request still reached it. In plain terms, the patch was skipped and the perimeter control was written narrowly enough to be walked around.
For organizations that let a contractor or MSP run internet-facing PeopleSoft, the exposure sits in the maintenance chain as much as in the software. If a managed platform misses an issued patch, a WAF rule can still leave employee-data systems reachable through a differently written URL.
2 sources · 8h ago
NVD KEV
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Known ransomware campaign use. EPSS 9% (95th percentile).
CISA federal remediation date Jun 15 · date passed
Timeline Sources Oct 6 SecurityWeek
FBI Blames Contractor’s Missed Patch for ShinyHunters Breach
The FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees.
original Oct 6 The Hacker News
FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach
FBI says a contractor failed to apply a security patch before a ShinyHunters breach stole personal details of thousands of employees.
original Part of the PlainSec briefing for 2026-10-06
Every edition of this story: FBI Breach Followed a Missed PeopleSoft Patch
More from today
Vulnerabilities & Exploits · Web App Attack
FBI Breach Followed a Missed PeopleSoft Patch Reuters reported the FBI removed an Accenture contractor after a missed Oracle PeopleSoft security patch let ShinyHunters steal personal details from thousands of FBI employees. The flaw at issue is CVE-2026-35273 .
Google-owned Mandiant says the group also used URL encoding to disguise the request well enough that a web application firewall rule did not recognize the blocked PeopleSoft Environment Management Hub endpoint, yet the request still reached it. In plain terms, the patch was skipped and the perimeter control was written narrowly enough to be walked around.
For organizations that let a contractor or MSP run internet-facing PeopleSoft, the exposure sits in the maintenance chain as much as in the software. If a managed platform misses an issued patch, a WAF rule can still leave employee-data systems reachable through a differently written URL.
2 sources · 8h ago
NVD KEV
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Known ransomware campaign use. EPSS 9% (95th percentile).
CISA federal remediation date Jun 15 · date passed
Timeline Sources Oct 6 SecurityWeek
FBI Blames Contractor’s Missed Patch for ShinyHunters Breach
The FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees.
original Oct 6 The Hacker News
FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach
FBI says a contractor failed to apply a security patch before a ShinyHunters breach stole personal details of thousands of employees.
original Part of the PlainSec briefing for 2026-10-06
Every edition of this story: FBI Breach Followed a Missed PeopleSoft Patch
More from today