Security advisories

Oracle PeopleSoft Zero-Day Vulnerability (CVE-2026-35273) Exploited by ShinyHunters

June 12, 2026

4 MINS READ

THE THREAT

On June 10th, 2026, Oracle disclosed a critical unauthenticated Remote Code Execution (RCE) vulnerability impacting its Oracle PeopleSoft PeopleTools application, tracked as CVE-2026-35273 (CVSS: 9.8). Successful exploitation of the flaw can result in full takeover of PeopleSoft Enterprise PeopleTools.

On June 11th, Mandiant and Google Threat Intelligence Group (GTIG) published a report confirming that exploitation of the flaw has been ongoing since at least May 27th, marking it a zero-day. The identified attacks were attributed to ShinyHunters, who leveraged CVE-2026-35273 as an initial access method to conduct data extortion attacks.

As exploitation is ongoing, organizations utilizing Oracle PeopleSoft should ensure that relevant patches are applied as soon as possible.

What we’re doing about it

What you should do about it

Additional information

ShinyHunters is a financially motivated threat actor that has been active since 2019. ShinyHunters has been known to conduct data extortion operations using social engineering and voice phishing (vishing) to gain access to enterprise environments and exfiltrate data. Mandiant and GTIG identified ShinyHunters exploiting CVE-2026-35273 to gain initial access to target organizations, two weeks prior to the patch release. Once initial access was gained, the threat actors deployed customized MeshCentral agents disguised as legitimate cloud endpoints, which they used to run queries, perform lateral movement, and deploy custom scripts. Data was exfiltrated from target environments and posted on ShinyHunters' Data Leak Site (DLS) on June 9th.

GTIG indicates that they notified over 100 global organizations whose IP addresses “correlated with potentially vulnerable endpoints”, noting that the majority of these organizations were in the United States, and that 68% of them were in the higher education sector. This sector's heavy reliance on Enterprise Resource Planning (ERP) platforms like Oracle PeopleSoft for managing student, financial, and HR data makes it a high-value target for extortion groups seeking large, monetizable datasets. eSentire's Threat Intelligence team assesses with medium confidence that because the campaign has been publicized, ShinyHunters may try to rapidly exploit Internet-exposed Oracle PeopleSoft applications before organizations are able to apply patches. Given that exploitation of CVE-2026-35273 is ongoing, organizations should ensure that relevant patches or mitigation steps outlined are applied as soon as possible.

Impacted Products List
PeopleSoft Enterprise PeopleTools Version 8.61
Version 8.62
Indicators of Compromise (IOCs) Identified by GTIG
142[.]11[.]200[.]186 Staging & C2 IP Address
142[.]11[.]200[.]187 Staging & C2 IP Address
142[.]11[.]200[.]188 Staging & C2 IP Address
142[.]11[.]200[.]189 Staging & C2 IP Address
142[.]11[.]200[.]190 Staging & C2 IP Address
azurenetfiles[.]net Staging & C2 Domain
2ab684d93c1553fad87041b4dea97188a97e78589deee2a7bacff905564f3a35 Attacker Command History
f02a924c9ff92a8780ce812511341182c6b509d45bc59f3f7b522e37225d24fc Pre-configured Windows Agent
d83fdb9e53c5ff03c4cb0451ea1bebd79b53f29eadc1e2fa394c7af13a86ce2f Pre-configured Windows Agent
c7e9332731b06644fc73e0046a2a89eaa59b09f54250e9bd622467187351711f Pre-configured Windows Agent
68257a6f9ff196179ec03624e849927f26599eb180a7c82e14ef5bc4e93bc309 Unconfigured Linux agent

References:

[1] https://www.oracle.com/security-alerts/alert-cve-2026-35273.html 
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-35273 
[3] https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit

Back to Security Advisories

Speak With A Security Expert Now

TALK TO AN EXPERT
View Most Recent Advisories