Two critical remote code execution vulnerabilities — both rated 9.8 out of 10 — are being actively exploited in attacks against Oracle PeopleSoft and Splunk Enterprise. These flaws allow attackers to take full control of affected systems without needing a password or any action from a user.
- Oracle PeopleSoft (CVE-2026-35273, CVSS 9.8): A critical RCE flaw in PeopleSoft PeopleTools. Attackers only need network access over HTTP — no login required. The ShinyHunters extortion group actively exploited this vulnerability between 27 May and 9 June 2026, targeting organisations running PeopleSoft for HR and finance management.
- Splunk Enterprise (CVE-2026-20253, CVSS 9.8): A critical vulnerability allowing unauthenticated file operations and remote code execution. Splunk has released patches and advises immediate action.
- CISA has added multiple related vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog this month, including a Google Chrome V8 flaw (CVE-2026-11645), a Cisco SD-WAN zero-day (CVE-2026-20245), and an Arista EOS vulnerability (CVE-2026-7473).
- Who is at risk: Any organisation running Oracle PeopleSoft for HR or finance, or Splunk for security monitoring and log management, should treat this as urgent.
Apply available patches immediately. If you use either product and are uncertain of your exposure, contact your IT provider. These are high-value targets for ransomware and data theft groups, and active exploitation is confirmed.
Sources: CISA Known Exploited Vulnerabilities Catalog | OpenText Cybersecurity Community | SecurityWeek