ShinyHunters is again mass exploiting a critical flaw in Oracle’s PeopleSoft Enterprise PeopleTools, triggering fresh warnings from Google’s threat intelligence team and incident responders tracking the campaign.[10][11][15] The vulnerability at the center of the attacks, CVE‑2026‑35273, is a remote code execution bug rated 9.8 on the CVSS v3.1 scale and stems from missing authentication in the Updates Environment Management component, reachable over HTTP.[1][4][6] Oracle issued an out‑of‑band Security Alert on June 10, 2026 and subsequently referenced the issue in its June Critical Patch Update, but current exploitation underscores that many internet‑facing PeopleSoft systems remain exposed.[1][2][3]
The renewed activity builds on an earlier wave of compromises between May 27 and June 9, 2026, when ShinyHunters—tracked by Google as UNC6240—used CVE‑2026‑35273 as a zero‑day to break into Oracle PeopleSoft application infrastructure, particularly in the education sector.[5][12] During that first campaign, Mandiant and Google Threat Intelligence observed intrusion and extortion operations consistent with exploitation of the flaw, which allowed attackers to execute arbitrary code on vulnerable PeopleSoft servers without credentials or user interaction.[5][12] Those attacks prompted Oracle’s emergency alert and a flurry of guidance from national cybersecurity agencies warning that successful exploitation could lead to total compromise of PeopleSoft Enterprise PeopleTools environments.[1][3][7]
In its latest advisory, Google reports that ShinyHunters has shifted from targeted intrusions to a broader “mass exploitation” model, expanding beyond education into multiple sectors worldwide.[10][11][15] Researchers say the group has adapted its exploit chain to evade common web application firewall rules, including by abusing the Environment Management Hub (PSEMHUB) interface and using percent‑encoded paths and crafted POST requests to the hub and related JSP endpoints.[10][14] External reporting indicates this updated tooling is being used to gain initial access, deploy payloads, and then extort victims by threatening data theft and disruption of mission‑critical PeopleSoft services.[11][12]
Technical analyses of CVE‑2026‑35273 agree that the bug is “easily exploitable” and allows an unauthenticated attacker with network access via HTTP to fully compromise PeopleSoft Enterprise PeopleTools.[1][4][6] Oracle and multiple vulnerability databases list PeopleTools versions 8.61 and 8.62 as affected, with some advisories warning that earlier, unsupported releases may also be at risk because they include the same Environment Management functionality.[1][4][6][14] Security agencies have stressed that exploitation requires no user interaction and that successful attacks can have high impact on confidentiality, integrity and availability, effectively handing an attacker control over the application stack and any data processed by it.[3][7]
The current campaign has prompted updated guidance urging organizations to apply Oracle’s patches or workarounds without delay and to harden exposed PeopleSoft infrastructure.[1][3][8][10] Oracle’s alert and subsequent commentary recommend upgrading PeopleTools to fixed versions, disabling the Environment Management Hub (EMHub) service in multi‑server configurations, or removing the PSEMHUB application outright in single‑server setups where feasible.[1][8][10] Google’s threat intelligence team further advises reviewing PIA WebLogic access logs for requests to /PSEMHUB/ and percent‑encoded variants, with particular scrutiny on external POST requests to hub endpoints and JSP files that may indicate exploit attempts.[10][14]
Defenders are also being told to treat any unpatched PeopleSoft environment as potentially compromised, especially if it has been reachable from the internet during the recent exploitation windows.[3][7][10] Recommended follow‑up includes hunting for anomalous administrative actions, web‑shell or backdoor deployment, and signs of data staging for exfiltration, along with tightening network segmentation and access controls around PeopleSoft servers.[7][10][13] With ShinyHunters actively iterating on its exploit and widening its victim pool, the combination of a trivially exploitable RCE and slow patch uptake leaves Oracle PeopleSoft customers facing a high‑stakes race to close CVE‑2026‑35273 before the extortion group finds them.[1][10][11]
References
- Oracle Security Alert Advisory – CVE-2026-35273
- Oracle Critical Security Patch Update Advisory – June 2026
- Critical Vulnerability in Oracle PeopleSoft Enterprise PeopleTools
- Text Form of Oracle Security Alert – CVE-2026-35273 Risk Matrices
- ShinyHunters Targets Education Sector with Oracle …
- CVE-2026-35273 | Tenable®
- CYBER ADVISORY
- Security Alert CVE-2026-35273 Released – Oracle Blogs
- ShinyHunters Renewed Mass Exploitation Campaign …
- Google warns ShinyHunters is mass-exploiting Oracle …
- Oracle PeopleSoft servers under attack, Oracle pushes out- …
- CVE-2026-35273: Missing Authentication for Critical Function
- ShinyHunters Bypass PeopleSoft WAF Rules for CVE-2026 …
- ShinyHunters hackers expanded attacks on Oracle’s …
