Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters

2026-06-12T07:24:03Ze5571a47a6695c5fc761abb8f1175e86f4094b2a23f8945dc0f98850b38c91a7
BOD 26-04BitLockerCISACVE-2026-35273FBIGreatXMLKEVLangflowOnyxC2Oracle PeopleSoftPalo Alto NetworksRCEShinyHuntersSplunkalert fatiguearbitrary file writebypassexploitmalwaremitigationpatch prioritizationrecruitment sitesstealervulnerability managementzero-day

What happened

Multiple SecurityWeek reports: Google confirms exploitation of an Oracle PeopleSoft vulnerability (CVE-2026-35273) by the ShinyHunters group; Oracle has issued mitigations. Other notable stories: OnyxC2 stealer marketed as an enterprise-grade theft-as-a-service; active exploitation of a Langflow RCE allowing arbitrary file writes; a ‘GreatXML’ zero-day proof-of-concept that bypasses BitLocker via Microsoft Defender offline scan; Splunk and Palo Alto Networks released patches for severe vulnerabilities; CISA issued BOD 26-04 to prioritize patching using the KEV catalog; the FBI seized 13 sites,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
e5571a47a6695c5fc761abb8f1175e86f4094b2a23f8945dc0f98850b38c91a7
Enrichment time
2026-06-12T07:24:03Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.