Oracle PeopleSoft broad zero-day exploitation campaign
Exploitation Wave
Summary
Hide ▲
Show ▼
A broad PeopleSoft zero-day exploitation campaign exposed multiple organizations to compromise after attackers abused a previously unknown Oracle PeopleSoft vulnerability. The wave widened risk for organizations running the platform, including internal reporting environments. NAIC tied its own breach to the same campaign after an unauthorized actor reached part of its PeopleSoft environment.
Related Happenings
Oracle E-Business Suite May 2026 Critical Security Patch Update (CVE-2026-46817)
Security Patch Release
H score53
First: 29.06.2026 16:46
Last: 29.06.2026 16:46
Sources 1
About this happening:
Oracle's May 2026 Critical Security Patch Update addressed CVE-2026-46817 in Oracle E-Business Suite, a critical flaw in Oracle Payments that could let an...
Oracle E-Business Suite May 2026 Critical Security Patch Update (CVE-2026-46817)
Security Patch ReleaseAbout this happening: Oracle's May 2026 Critical Security Patch Update addressed CVE-2026-46817 in Oracle E-Business Suite, a critical flaw in Oracle Payments that could let an...
Oracle E-Business Suite unauth HTTP takeover security flaw (CVE-2026-46817)
Vulnerability
H score52
First: 29.06.2026 16:46
Last: 29.06.2026 16:46
Sources 1
About this happening:
Oracle E-Business Suite CVE-2026-46817 is under active exploitation, putting Oracle Payments deployments at takeover risk. The flaw allows unauthenticated HTTP a...
Oracle E-Business Suite unauth HTTP takeover security flaw (CVE-2026-46817)
VulnerabilityAbout this happening: Oracle E-Business Suite CVE-2026-46817 is under active exploitation, putting Oracle Payments deployments at takeover risk. The flaw allows unauthenticated HTTP a...
US National Association of Insurance Commissioners (NAIC) hit by network compromise
Incident
H score80
First: 29.06.2026 13:00
Last: 29.06.2026 13:00
Sources 1
How related:
The US National Association of Insurance Commissioners (NAIC) has suffered a security breach that has exposed US citizens’ credit rating data.
About this happening:
NAIC disclosed a security breach that exposed US citizens’ credit rating data and briefly disrupted operations tied to Oracle PeopleSoft. The breach was detected o...
US National Association of Insurance Commissioners (NAIC) hit by network compromise
IncidentHow related: The US National Association of Insurance Commissioners (NAIC) has suffered a security breach that has exposed US citizens’ credit rating data.
About this happening: NAIC disclosed a security breach that exposed US citizens’ credit rating data and briefly disrupted operations tied to Oracle PeopleSoft. The breach was detected o...
Oracle PeopleSoft PeopleTools zero-day RCE (CVE-2026-35273)
Vulnerability
H score58
First: 11.06.2026 22:39
Last: 11.06.2026 22:39
Sources 1
How related:
an unauthorized actor gained access to “a portion” of its environment through the exploitation of a zero-day vulnerability in Oracle PeopleSoft, which NAIC uses for internal financial reporting purposes.
About this happening:
Oracle PeopleSoft PeopleTools CVE-2026-35273 is a critical zero-day RCE affecting PeopleSoft Enterprise PeopleTools 8.61 and 8.62. Oracle released emergency mitigati...
Oracle PeopleSoft PeopleTools zero-day RCE (CVE-2026-35273)
VulnerabilityHow related: an unauthorized actor gained access to “a portion” of its environment through the exploitation of a zero-day vulnerability in Oracle PeopleSoft, which NAIC uses for internal financial reporting purposes.
About this happening: Oracle PeopleSoft PeopleTools CVE-2026-35273 is a critical zero-day RCE affecting PeopleSoft Enterprise PeopleTools 8.61 and 8.62. Oracle released emergency mitigati...
Latest development: 29.06.2026 23:40
Nissan says it suffered a data breach affecting current and former employees after attackers exploited an Oracle PeopleSoft zero-day associated with CVE-2026-35273. Oracle informed Nissan that personnel records of hundreds of companies may have been obtained and that Nissan was specifically targeted, with potentially exposed data including contact details, banking information, Social Security numbers, Social Insurance Numbers, National Identification Numbers, financial and tax information, and dependent and beneficiary data for employees in the United States, Canada, Mexico, and Brazil.
University of Nottingham hit by cyberattack
Incident
H score68
First: 11.06.2026 10:27
Last: 11.06.2026 10:27
Sources 1
About this happening:
The University of Nottingham said a well-known cybercriminal group accessed its student record system, exposing a significant amount of data affecting current students and...
University of Nottingham hit by cyberattack
IncidentAbout this happening: The University of Nottingham said a well-known cybercriminal group accessed its student record system, exposing a significant amount of data affecting current students and...
Timeline
-
29.06.2026 13:00 1 articles · 16d ago
Unauthorized actor exploits Oracle PeopleSoft zero-day against NAIC
Exploitation ObservedThe US National Association of Insurance Commissioners detected a breach in which an unauthorized actor gained access to a portion of its Oracle PeopleSoft environment by exploiting a zero-day vulnerability used for internal financial reporting purposes.
Show sources
- US Federal Insurance Regulator Confirms Data Breach Via Oracle Flaw — www.infosecurity-magazine.com — 29.06.2026 13:00
-
29.06.2026 13:00 3 articles · 16d ago
NAIC publicly discloses a breach exposing credit rating data
Initial DisclosureThe US National Association of Insurance Commissioners disclosed the breach to the public, saying the incident exposed US citizens’ credit rating data and that the event had been detected earlier in June.
Show sources
- US Federal Insurance Regulator Confirms Data Breach Via Oracle Flaw — www.infosecurity-magazine.com — 29.06.2026 13:00
- US Federal Insurance Regulator Confirms Data Breach Via Oracle Flaw — www.infosecurity-magazine.com — 29.06.2026 13:00
- NAIC says public data stolen in ShinyHunters' PeopleSoft breach — www.bleepingcomputer.com — 29.06.2026 23:30
-
29.06.2026 13:00 1 articles · 16d ago
NAIC restores most operations after PeopleSoft breach, with online invoice payments still unavailable
Mitigation Patch UpdateNAIC said it promptly contained the breach, blocked the attacker’s access, engaged outside counsel and cybersecurity experts, coordinated with the FBI, and returned most operations to normal while online invoice payment via PeopleSoft remained unavailable.
Show sources
- US Federal Insurance Regulator Confirms Data Breach Via Oracle Flaw — www.infosecurity-magazine.com — 29.06.2026 13:00