ShinyHunters Exploited an Oracle PeopleSoft Zero-Day for Two Weeks Before Disclosure as CVE-2026-35273 Lands on CISA's KEV Catalog
CVE-2026-35273, a CVSS 9.8 missing-authentication flaw in Oracle PeopleSoft PeopleTools, was exploited as a zero-day by UNC6240 before Oracle shipped mitigations and CISA set a June 15 federal deadline.