Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks

2026-06-11T19:24:06Z6b8057bcf83b8f4f72e4e071664e0fe8c12c814b50bafc8ab540b725f7637913
BitLockerCISA BOD 26-04CVE-2026-35273China targetingDesigo CCFBI website seizuresGreatXMLKEVLangflowMicrosoft Defender offline scanOnyxC2OraclePalo Alto NetworksPeopleSoftRCEShinyHuntersSiemensSplunkUniversity of Nottinghamalert fatigue','AI automationdata breachfalse positivesstealervulnerability managementzero-day

What happened

SecurityWeek roundup: Oracle released mitigations for a PeopleSoft vulnerability (CVE-2026-35273) amid reports of possible zero-day exploitation linked to ShinyHunters; researchers disclosed a ‘GreatXML’ zero‑day PoC that can bypass BitLocker by abusing Microsoft Defender offline scanning to obtain a SYSTEM shell; Splunk and Palo Alto Networks patched severe vulnerabilities enabling arbitrary file creation and protected-resource modification; Langflow RCE exploitation (unauthenticated arbitrary file write) is being abused in the wild; OnyxC2 stealer is being marketed as a $250/month enterprise

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
6b8057bcf83b8f4f72e4e071664e0fe8c12c814b50bafc8ab540b725f7637913
Enrichment time
2026-06-11T19:24:06Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks · Baitaphish