Back to Blog
2026-06-24· 6 min read

Oracle PeopleSoft Zero-Day: ShinyHunters Compromises 300+ Instances Across 100 Organizations

ShinyHunters exploited CVE-2026-35273, a CVSS 9.8 unauthenticated RCE in Oracle PeopleSoft, to compromise over 300 instances across 100+ organizations including universities and enterprises.

Zero-Day Oracle PeopleSoft ShinyHunters Enterprise Security CVE

The Attack Campaign


In late May 2026, the ShinyHunters extortion group began exploiting a critical zero-day vulnerability in Oracle PeopleSoft PeopleTools. By June 9, they claimed to have compromised **over 300 PeopleSoft instances across 100+ organizations**.


The Vulnerability: CVE-2026-35273


  • |Attribute | Details
  • |-----------|---------|

  • |CVE | CVE-2026-35273
  • |CVSS Score | 9.8 (Critical)
  • |Vector | Unauthenticated RCE over HTTP
  • |Affected Versions | PeopleTools 8.61 and 8.62
  • |Component | Updates Environment Management Hub (EMHub)
  • |User Interaction | None required
  • |Authentication | None required

  • This is as severe as it gets: any attacker who can reach a vulnerable PeopleSoft instance over HTTP can run arbitrary code on it.


    Timeline


  • |Date | Event
  • |------|-------|

  • |May 27 | Earliest observed exploitation (Mandiant/Arctic Wolf)
  • |June 9 | ShinyHunters claims 300+ instances across 100+ orgs
  • |June 10 | Oracle publishes out-of-band security alert
  • |June 11 | First public victim confirms: 40+ GB, ~500,000 student records
  • |June 15 | Eastman Kodak listed on leak site; 2.2M+ records threatened
  • |Mid-June | Amazon One Medical (8.8 TB) and Council of Europe claimed
  • |June 18 | Kodak extortion deadline passes

  • Who Was Affected


    Universities (Primary Targets)

    PeopleSoft is widely used in higher education for student records, HR, and financial systems. Universities bore the brunt of the attack.


    Enterprises

  • Eastman Kodak 2.2M+ records threatened
  • Amazon One Medical 8.8 TB of data claimed
  • Council of Europe 429,000+ documents
  • NAIC (National Association of Insurance Commissioners) 3.1TB stolen

  • How ShinyHunters Operates


    1. **Scan the internet** for vulnerable PeopleSoft instances

    2. **Exploit CVE-2026-35273** to gain unauthenticated access

    3. **Exfiltrate sensitive data** (HR, financial, student records)

    4. **Extort victims** with "pay or leak" demands

    5. **Publish data** on dark web leak sites if unpaid


    How to Protect Yourself


    Immediate Actions

    1. **Patch PeopleSoft immediately** to the latest fixed version

    2. **Audit EMHub access** for unauthorized entries

    3. **Monitor for data exfiltration** indicators

    4. **Review network logs** for suspicious HTTP traffic to EMHub endpoints


    Long-Term Security

  • Implement web application firewalls (WAF)
  • Deploy runtime application self-protection (RASP)
  • Regular security assessments of ERP systems
  • Network segmentation for critical applications

  • This Is the Second Oracle ERP Zero-Day in 8 Months


  • |Vulnerability | CVE-2026-35273 | CVE-2025-61882
  • |---------------|----------------|----------------|

  • |Product | PeopleSoft PeopleTools | E-Business Suite
  • |CVSS | 9.8 | 9.8
  • |Threat Actor | ShinyHunters | Cl0p
  • |First Exploited | May 2026 | August 2025
  • |Outcome | Data theft extortion | Data theft extortion

  • Check Your Domain


    Scan your domain for vulnerabilities and exposed services.


    [Free security scan](https://vaarta.space)


    Ready to check your domain security?

    Run a free scan to identify potential vulnerabilities.

    Start Free Scan