What is CVE-2026-35273?
CVE-2026-35273 is a critical vulnerability actively exploited by the ShinyHunters (UNC6240) group in Oracle PeopleSoft systems. Targeting the education sector, this campaign aims for data theft and extortion; organizations must immediately apply patches and enhance network monitoring.
Azərbaycanca: CVE-2026-35273 ShinyHunters (UNC6240) qrupu tərəfindən Oracle PeopleSoft sistemlərində aktiv istismar edilən kritik boşluqdur. Təhsil sektorunu hədəf alan bu kampaniya məlumat oğurluğu və şantaj məqsədi daşıyır, təşkilatlar dərhal yamaqları tətbiq etməli və şəbəkə monitorinqini gücləndirməlidir.
Related CVEs
link basis: shared threat actors: ShinyHunters, UNC6240; shared vendors: Google Threat Intelligence Group, Mandiant, Oracle
FAQ2
Which systems does CVE-2026-35273 target, and which group is actively exploiting it?
The vulnerability targets Oracle PeopleSoft systems and is actively exploited by the ShinyHunters (UNC6240) group.
What is the main objective of the campaign involving CVE-2026-35273, and what should organizations do?
The campaign targets the education sector for data theft and extortion; organizations must immediately apply patches and enhance network monitoring.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.