Vulnerabilities · 4h ago

ShinyHunters Claim PeopleSoft Zero-Day Broke FBI Defenses

ShinyHunters claimed it used a new Oracle PeopleSoft zero-day, CVE-2026-35273, to break into an FBI system and steal employee data, while analysts said the exposure goes beyond a simple patch issue. Security voices singled out PeopleSoft’s Environment Management Hub and Integration Broker as components that should not be left reachable from the public internet.

The problem is the management path, not normal user login. If attackers can reach those admin modules, they can use the admin plane as a back door into the PeopleSoft environment, and a server-side foothold can expose credentials and other secrets the system can read.

For PeopleSoft shops that expose those components, the lasting risk is that a patched core can still sit behind an internet-facing management layer. The reporting also leaves open how many deployments have that path open, which is the exposure that now matters most.

CVE-2026-35273

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Known ransomware campaign use. EPSS 9% (95th percentile).

CISA federal remediation date Jun 15 · date passed

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-10-06

Editions

Related stories