A major ransomware group has taken advantage of a serious vulnerability in Oracle's PeopleSoft software, impacting nearly 100 organizations. This flaw, identified as CVE-2026-35273, has a critical severity rating of 9.8 out of 10, marking it as one of the most significant vulnerabilities of the year. The group, known as ShinyHunters, has reportedly been exploiting this weakness for over two weeks prior to Oracle's acknowledgment. The vulnerability is classified as server-side request forgery (SSRF), which permits attackers to send requests from a compromised server to other systems within the targeted organization. Although Oracle has released a temporary mitigation measure, a comprehensive fix for the issue is still pending. Reports indicate that some victims have already received extortion demands, highlighting the urgent need for organizations using PeopleSoft to address this vulnerability promptly.
Critical PeopleSoft Vulnerability Leads to Data Theft for Numerous Organizations
A severe flaw in Oracle's PeopleSoft software has been exploited by a ransomware group, affecting around 100 organizations and leading to significant data theft.
