// Alert

Oracle Health threat report

Oracle's July 2026 Critical Patch Update permanently fixed CVE-2026-35273, a privilege-escalation zero-day in PeopleSoft PeopleTools (CVSS 9.8) that ShinyHunters actively exploited to breach over 100 organizations worldwide—primarily universities—between May 27 and June 9, 2026. The vulnerability enabled unauthenticated remote code execution; 68% of affected organizations were higher-education institutions, with confirmed data exposures including 40+ gigabytes from University of Nottingham covering nearly 500,000 students. Oracle issued an out-of-band alert on June 10 after exploitation was already underway for two weeks, underscoring disclosure delays in critical enterprise software.

// Get alerts for Oracle Health