ProBackend
cybersecurity
Jun 15, 20265 min read

Oracle PeopleSoft RCE Vulnerability CVE-2026-35273: Emergency Alert for Zero-Day Exploited by ShinyHunters

Critical unauthenticated remote code execution flaw (CVSS 9.8) in Oracle PeopleSoft PeopleTools actively exploited by ShinyHunters extortion gang targeting 300+ instances across 100+ organizations.

Overview

Oracle has issued an emergency security alert for a critical unauthenticated remote code execution (RCE) vulnerability in PeopleSoft PeopleTools, tracked as CVE-2026-35273. The vulnerability carries a CVSS base score of 9.8 — the highest severity rating — and is actively being exploited in the wild by the ShinyHunters extortion group.

This zero-day flaw allows attackers to execute arbitrary code on affected PeopleSoft systems without requiring authentication, making it exceptionally dangerous. Oracle has confirmed that the vulnerability affects PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62, and the company has released emergency mitigations while a permanent patch is prepared.

See our guide on CVE detection and response for best practices in handling critical vulnerabilities like this one.

Technical Details

Vulnerability Characteristics

  • CVE ID: CVE-2026-35273
  • CVSS Score: 9.8 (Critical)
  • Attack Vector: Network
  • Authentication Required: No
  • Confidentiality Impact: High
  • Integrity Impact: High
  • Availability Impact: High

The vulnerability resides within Oracle PeopleSoft PeopleTools, a component of the broader PeopleSoft enterprise application suite. According to Oracle's advisory: "This vulnerability is remotely exploitable without authentication. If successfully exploited, this vulnerability may result in remote code execution."

Affected Versions

  • PeopleSoft Enterprise PeopleTools 8.61
  • PeopleSoft Enterprise PeopleTools 8.62

Organizations running these versions are strongly advised to implement the emergency mitigations immediately.

ShinyHunters Attack Campaign

Background on the Threat Actor

ShinyHunters is a well-established extortion group known for targeting cloud-based SaaS platforms, customer relationship management (CRM) systems, and enterprise data repositories. The group typically follows a consistent playbook:

  1. Gain unauthorized access to high-value data repositories
  2. Download massive volumes of corporate and customer data
  3. Demand ransom payments to prevent public data leaks
  4. Threaten to leak stolen data if demands are not met

See our threat actor profile on ShinyHunters to understand their tactics, techniques, and procedures.

The Attack Campaign Details

While Oracle's initial advisory did not explicitly confirm active exploitation, BleepingComputer first reported that ShinyHunters was targeting Oracle PeopleSoft systems in data theft attacks. Subsequent investigation confirmed that CVE-2026-35273 is the zero-day vulnerability being exploited in these attacks.

The ShinyHunters group confirmed to BleepingComputer that they are behind the PeopleSoft breaches, claiming to use a "gadget chain" of both previously known vulnerabilities and zero-day exploits to compromise PeopleSoft instances.

Attack Statistics

According to security researchers, the attackers have:

  • Gained access to approximately 300 instances
  • Compromised over 100 organizations globally
  • Operated for a significant period before detection

Indicators of Compromise (IOCs)

Cybersecurity researcher Michael R identified several IP addresses associated with the attack infrastructure:

142.11.200[.]186 142.11.200[.]187 142.11.200[.]188
142.11.200[.]189 142.11.200[.]190 108.174.202[.]99
176.120.22[.]24

Security teams should monitor for connections to these IP addresses and block them at perimeter firewalls where possible.

Mandiant Report: Targeting the Education Sector

Google Cloud's Threat Intelligence team (formerly Mandiant) released a detailed report confirming that threat actors exploited CVE-2026-35273 as a zero-day vulnerability primarily targeting organizations in the education sector.

Key Findings from Mandiant Report

  • Primary Target Sector: Higher education institutions
  • Geographic Focus: United States (majority of targets)
  • Target Statistics: Over 100 global organizations notified
  • Attack Phase: Active scanning and exploitation observed

Mandiant's report states: "Upon becoming aware of active scanning and exploitation, we initiated notifications to over 100 global organizations whose IP addresses correlated with potentially vulnerable endpoints. Most of these organizations were based in the United States, and 68 percent operated within the higher education sector."

This targeting pattern suggests a strategic focus on educational institutions, which often possess valuable research data, student records, and administrative information — making them attractive targets for data theft campaigns.

Mitigations and Response

Immediate Actions Required

Oracle has released emergency mitigations to address the vulnerability. Organizations are advised to:

  1. Apply Emergency Mitigations: Implement Oracle's emergency mitigation measures immediately. These mitigations are documented in Oracle support document CPU187.

  2. Network Segmentation: Isolate PeopleSoft systems from untrusted networks where possible.

  3. Block Known IOCs: Implement firewall rules to block the identified malicious IP addresses.

  4. Monitor for Indicators: Deploy detection rules for known attack patterns and suspicious activity on PeopleSoft servers.

  5. Review Access Logs: Examine PeopleSoft access logs for any signs of unauthorized access prior to patching.

Patch Timeline

While emergency mitigations are available, Oracle has confirmed that a permanent patch is being prepared and will be released through the regular Critical Patch Update (CPU) cycle. Organizations should:

  • Monitor Oracle Security Alerts for the patch release
  • Plan and test patch deployment during scheduled maintenance windows
  • Prioritize patching in production environments

Long-term Recommendations

  1. Vulnerability Management: Implement comprehensive vulnerability scanning for all Oracle applications
  2. Patch Management: Establish strict patch management policies with defined timelines
  3. Security Monitoring: Deploy advanced threat detection for PeopleSoft environments
  4. Incident Response Planning: Ensure incident response plans address zero-day vulnerabilities
  5. Third-party Assessments: Consider engagement with security vendors for specialized PeopleSoft security assessments

Industry Context and Lessons Learned

Pattern of Zero-day Exploitation

The ShinyHunters attack on PeopleSoft follows a disturbing pattern where threat actors exploit critical vulnerabilities before vendors can release patches. This vulnerability joins a list of high-profile zero-day exploits that have caused significant damage:

  • Apache Log4j (2021): CVE-2021-44228
  • Exchange Server (2021): CVE-2021-26855 (ProxyLogon)
  • Active Directory Web Services (2022): CVE-2022-26923
  • HP Printers (2023): Multiple zero-day vulnerabilities

See our comprehensive guide on zero-day vulnerability response for organizational preparedness.

The Zero-day Marketplace

The existence of active exploits for CVE-2026-35273 suggests that the vulnerability may have been known in security research circles before Oracle's public advisory. The timeline from vulnerability identification to widespread exploitation highlights the urgency of implementing emergency mitigations as soon as they become available.

Organization Readiness

The Mandiant report underscores the importance of proactive security monitoring and rapid response capabilities. Organizations that received early warnings were able to take preventive measures before widespread exploitation occurred.

Conclusion

CVE-2026-35273 represents one of the most critical vulnerabilities facing Oracle PeopleSoft deployments in recent memory. With a CVSS score of 9.8 and confirmed active exploitation by the ShinyHunters group, organizations must act immediately to protect their PeopleSoft environments.

The combination of unauthenticated remote code execution, confirmed exploitation by a sophisticated threat actor, and targeting of high-value data repositories creates a perfect storm for potential data breaches. Organizations running PeopleTools versions 8.61 and 8.62 should:

  • Immediately implement Oracle's emergency mitigations
  • Block identified malicious IP addresses
  • Review access logs for signs of compromise
  • Monitor Oracle security advisories for the permanent patch
  • Prepare incident response plans in case of compromise

This is not a drill — the vulnerability is actively being exploited, and organizations that delay response risk significant data breaches and regulatory consequences.

More blogs