CRITICAL: Oracle PeopleSoft Zero-Day CVE-2026-35273 Powers ShinyHunters Spree Across 100+ Universities
ShinyHunters weaponized an unauthenticated 9.8 CVSS RCE in Oracle PeopleSoft PeopleTools (CVE-2026-35273) as a zero-day from May 27 through June 9, breaching the University of Nottingham and over a hundred mostly higher-education organizations before Oracle issued an out-of-band advisory on June 10.