Oracle PeopleSoft Zero-Day: ShinyHunters Compromises 300+ Instances Across 100 Organizations
ShinyHunters exploited CVE-2026-35273, a CVSS 9.8 unauthenticated RCE in Oracle PeopleSoft, to compromise over 300 instances across 100+ organizations including universities and enterprises.
The Attack Campaign
In late May 2026, the ShinyHunters extortion group began exploiting a critical zero-day vulnerability in Oracle PeopleSoft PeopleTools. By June 9, they claimed to have compromised **over 300 PeopleSoft instances across 100+ organizations**.
The Vulnerability: CVE-2026-35273
|-----------|---------|
This is as severe as it gets: any attacker who can reach a vulnerable PeopleSoft instance over HTTP can run arbitrary code on it.
Timeline
|------|-------|
Who Was Affected
Universities (Primary Targets)
PeopleSoft is widely used in higher education for student records, HR, and financial systems. Universities bore the brunt of the attack.
Enterprises
How ShinyHunters Operates
1. **Scan the internet** for vulnerable PeopleSoft instances
2. **Exploit CVE-2026-35273** to gain unauthenticated access
3. **Exfiltrate sensitive data** (HR, financial, student records)
4. **Extort victims** with "pay or leak" demands
5. **Publish data** on dark web leak sites if unpaid
How to Protect Yourself
Immediate Actions
1. **Patch PeopleSoft immediately** to the latest fixed version
2. **Audit EMHub access** for unauthorized entries
3. **Monitor for data exfiltration** indicators
4. **Review network logs** for suspicious HTTP traffic to EMHub endpoints
Long-Term Security
This Is the Second Oracle ERP Zero-Day in 8 Months
|---------------|----------------|----------------|
Check Your Domain
Scan your domain for vulnerabilities and exposed services.
[Free security scan](https://vaarta.space)
Related Articles
CVE-2026-20253: Critical Splunk Enterprise RCE Vulnerability Under Active Attack
A CVSS 9.8 critical vulnerability in Splunk Enterprise allows unauthenticated remote code execution. CISA confirms active exploitation. Patch immediately to versions 10.2.4 or 10.0.7.
2026-06-24Check Point VPN Zero-Day (CVE-2026-50751): Qilin Ransomware Exploits Authentication Bypass
A critical CVSS 9.3 vulnerability in Check Point VPN allows unauthenticated access. Qilin ransomware affiliates have been exploiting it since May 2026. Patch immediately.
2026-05-12Spring4Shell CVE-2022-22965 — RCE Vulnerability Explained | Vaarta
Complete analysis of Spring4Shell (CVE-2022-22965). How the RCE exploit works, affected versions, detection methods, and remediation steps for Java apps.
Ready to check your domain security?
Run a free scan to identify potential vulnerabilities.
Start Free Scan