Oracle Addresses PeopleSoft Zero-Day Vulnerability Under Active Attack

Oracle's out-of-band advisory warns of a critical PeopleSoft zero-day being actively exploited by the ShinyHunters group.

By Central
Enterprises running PeopleSoft 8.61 or 8.62 face an urgent threat from a zero-day vulnerability.
Highlights
  • The vulnerability, CVE-2026-35273, enables unauthenticated remote code execution on affected PeopleSoft instances.
  • ShinyHunters has targeted over 300 PeopleSoft instances across more than 100 organizations globally.
  • The education sector is the most affected, with universities like the University of Nottingham confirming breaches.

Oracle has issued an out-of-band security advisory to address a critical zero-day vulnerability in PeopleSoft that is already being actively exploited by the ShinyHunters hacker group, according to multiple incident reports. The vulnerability, designated CVE-2026-35273, allows an unauthenticated attacker to achieve remote code execution on affected systems, posing an immediate and severe risk to enterprises relying on the widely deployed ERP suite.

The Vulnerability: CVE-2026-35273

The flaw resides in PeopleSoft Enterprise PeopleTools, versions 8.61 and 8.62, and may also impact PeopleSoft Enterprise Applications. Oracle has classified the issue as critical. Because the attack vector requires no authentication and enables full remote code execution, any exposed and unmitigated PeopleSoft instance is effectively a direct entry point for adversaries. At the time of the advisory, Oracle has released only mitigations rather than a complete patch, elevating the urgency for organizations to apply the recommended configuration changes immediately.

Active Exploitation by ShinyHunters

Reports from multiple sources confirm that hackers claiming affiliation with the ShinyHunters group have targeted more than 300 PeopleSoft instances across over 100 organizations. The attackers stated they chained older known vulnerabilities with this zero-day to gain access to sensitive data stored in PeopleSoft environments. Independent researchers have corroborated the attacks, and Mandiant CTO Charles Carmakal issued a warning about active zero-day exploitation. TrendAI researchers were credited by Oracle for reporting CVE-2026-35273, and Dustin Childs, Head of Threat Awareness at TrendAI’s Zero Day Initiative, noted that exploitation is currently limited but remains under active investigation.

Which Sectors Are Being Hit Hardest

The education sector has been disproportionately affected in this campaign. The University of Nottingham confirmed a significant data breach, and Bleeping Computer reported that educational institutions represent the largest share of confirmed victims. Given that universities and large public-sector organizations are heavy users of PeopleSoft for HR, payroll, finance, and campus operations, the targeting aligns with ShinyHunters’ established pattern of stealing large datasets for extortion. The group previously conducted a massive data-theft campaign against Salesforce customers.

Oracle’s Response: Mitigations, Not a Full Patch

Oracle’s advisory stops short of explicitly confirming in-the-wild exploitation, but the language is unambiguous about the risk. The company stated, “We consider implementation of the recommended mitigations to be a high-priority risk reduction measure and strongly recommend immediate action to address the identified exposure.” This phrasing is consistent with past Oracle advisories where exploitation was later confirmed by CISA or independent researchers, as seen recently with a 2024 Oracle WebLogic vulnerability that CISA warned was being exploited in active attacks.

What Affected Organizations Should Do Now

Any organization running PeopleSoft Enterprise PeopleTools versions 8.61 or 8.62 should treat this as an active threat. The first step is to review and apply the mitigations outlined in Oracle’s security alert for CVE-2026-35273 without delay. Additionally, security teams should audit PeopleSoft instances for signs of unauthorized access, review logs for unusual authentication patterns, and rotate credentials associated with PeopleSoft service accounts. For organizations that have not yet applied the mitigations, isolating affected systems from external network access is a prudent interim measure. Given the ShinyHunters group’s demonstrated ability to chain vulnerabilities for data theft, deploying a multi-layered endpoint protection solution and enabling robust logging and monitoring on PeopleSoft environments are strongly recommended. Affected users should also enable multi-factor authentication on all administrative interfaces and monitor for any unusual data export activity.

Share This Article