An unpatched PeopleSoft vulnerability is being exploited as a zero-day by extortionists; CISOs must scan their systems for indicators and prioritize Oracle patches.
Oracle has patched a critical vulnerability in PeopleSoft Suite (CVE-2026-35273) enabling unauthenticated remote code execution that is already being actively exploited in targeted data theft campaigns by the ShinyHunter group.