VYPR
AI Brief2026-06-12· generated Jun 12, 2026

Oracle PeopleSoft Zero-Day Under Active Attack

ShinyHunters exploits an Oracle PeopleSoft zero-day against over 100 organizations as Microsoft ships its largest Patch Tuesday on record.

Oracle PeopleSoft zero-day under active exploitation by ShinyHunters, Oracle issues emergency out-of-band alert. CVE-2026-35273 is a critical unauthenticated remote code execution vulnerability in Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 that is being actively exploited in the wild by the threat actor ShinyHunters. As The Hacker News reported, the group has leveraged this flaw to breach over 100 organizations, primarily targeting universities and educational institutions globally. Mandiant confirmed the attacks and noted the group is using the access for data theft and extortion. Oracle pushed an out-of-band security alert and mitigation guidance, as BleepingComputer detailed. Organizations running affected PeopleTools versions should apply the emergency patch immediately and audit for signs of compromise.

Microsoft ships record Patch Tuesday with 206 CVEs, including three zero-days and critical Windows HTTP.sys and TCP/IP flaws. BleepingComputer reported that June 2026 is the largest Patch Tuesday on record. Among the most critical items: CVE-2026-47291, an integer overflow in Windows HTTP.sys that allows unauthenticated remote code execution; CVE-2026-45657, a use-after-free in the Windows Kernel rated at 9.8 CVSS that is under active attack; and CVE-2026-42904, a heap-based buffer overflow in Windows TCP/IP enabling privilege escalation over an adjacent network. The Record noted that one of the zero-days is already being exploited in the wild, and Cisco Talos released Snort rules covering the most dangerous bugs. Admins should prioritize the HTTP.sys and kernel flaws for immediate patching.

Adobe discloses 25 vulnerabilities across Campaign Classic and ColdFusion, including two critical CVSS 10.0 flaws. CVE-2026-48303 and CVE-2026-47938 both carry a CVSS score of 10.0 and affect Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier. The first is an incorrect authorization vulnerability that can lead to arbitrary code execution in the context of the current user; the second is a server-side request forgery (SSRF) flaw enabling privilege escalation without user interaction. Separately, CVE-2026-47928 is a critical improper input validation bug in ColdFusion versions 2023.19, 2025.8 and earlier that also results in arbitrary code execution. As Vypr Intelligence noted, these represent the highest-severity items in Adobe's June disclosure batch. Organizations using ACC or ColdFusion should update to the latest builds.

Splunk Enterprise and Splunk Cloud Platform hit by critical unauthenticated file manipulation flaw. CVE-2026-20253 (CVSS 9.8) affects Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and 10.2.2510.14. An unauthenticated attacker can create or truncate arbitrary files through a PostgreSQL sidecar service endpoint, potentially leading to remote code execution or data corruption. SecurityWeek and Cyber Security News both highlighted the severity of this flaw, which requires no authentication or user interaction. Splunk administrators should prioritize upgrading to patched versions.

Roxy-WI disclosed 14 vulnerabilities including three critical CVSS 9.9 flaws enabling remote code execution. CVE-2026-45552, CVE-2026-45556, and CVE-2026-45558 all affect Roxy-WI versions 8.2.6.4 and prior, a web interface for managing HAProxy, Nginx, Apache, and Keepalived servers. CVE-2026-45552 stems from missing authentication on install blueprint endpoints; CVE-2026-45556 is a path traversal via the config_file_name parameter in WAF rule saving; and CVE-2026-45558 allows arbitrary file write through HAProxy section-save endpoints. Vypr Intelligence reported the full disclosure. Given Roxy-WI's role in managing critical infrastructure proxies, these flaws present a significant lateral-movement risk for attackers who gain initial access.

IoT and OT devices hit by hard-coded credentials and platform-wide signing flaws. CVE-2026-10557 affects Yarbo Android and iOS applications, which contain hard-coded MQTT broker credentials identical for all users and devices, extractable via APK decompilation. CISA's advisory warned that this could allow remote attackers to control connected robotic equipment. Separately, CVE-2026-28742 impacts Naxclow devices, which use a uniform request-signing scheme based on a hard-coded, platform-wide salt embedded in every firmware image — once recovered, an attacker can forge signatures for arbitrary device commands. CISA's advisory noted that no authentication is required for exploitation. Both flaws underscore the persistent problem of embedded secrets in consumer and industrial IoT ecosystems.

Synthesized by Vypr AI