CVE-2026-35273: ShinyHunters Hits PeopleSoft, 100+ Orgs Breached
Oracle PeopleSoft zero-day CVE-2026-35273 exploited in the wild. ShinyHunters claims 100+ breaches including University of Nottingham — 500,000 student records stolen.
·8 min read
Topic
4 articles
Oracle PeopleSoft zero-day CVE-2026-35273 exploited in the wild. ShinyHunters claims 100+ breaches including University of Nottingham — 500,000 student records stolen.
Cisco disclosed CVE-2026-20245, its 7th SD-WAN zero-day of 2026, enabling root access via crafted file upload with no patch yet. All deployment types are affected, including FedRAMP.
CVE-2026-3055 is a CVSS 9.3 out-of-bounds memory read in Citrix NetScaler ADC and Gateway actively exploited since March 27, 2026. Patch versions and mitigation inside.
CVE-2026-33017 is a CVSS 9.3 RCE in Langflow affecting all versions up to 1.8.1. Attackers exploited it within 20 hours with no PoC. Upgrade to 1.9.0 immediately.