Oracle has issued an out-of-band security alert and patch for a critical zero-day vulnerability, CVE-2026-35273, affecting its PeopleSoft PeopleTools enterprise software. The flaw is a remotely exploitable, unauthenticated vulnerability that can lead to remote code execution (RCE), posing a severe risk to affected organizations. The emergency action was prompted by active in-the-wild exploitation attributed to the ShinyHunters extortion group. The group claims to have breached over 100 organizations, particularly in the education sector, by chaining this zero-day with other vulnerabilities to steal large volumes of data for extortion campaigns. Organizations using PeopleSoft PeopleTools versions 8.61 and 8.62 are urged to apply the patch immediately.
CVE-2026-35273The vulnerability allows a remote attacker, without needing any credentials, to execute arbitrary code on a vulnerable PeopleSoft server. This effectively gives the attacker full control over the server, allowing them to steal data, install additional malware, or pivot deeper into the victim's network.
The vulnerability is a zero-day that is confirmed to be actively exploited in the wild. The ShinyHunters threat group is using the flaw as part of a "gadget chain"—a sequence of vulnerabilities—to compromise PeopleSoft servers. Mandiant's CTO has publicly confirmed the active attacks. ShinyHunters claims to have breached over 300 instances at more than 100 organizations, with a heavy focus on universities.
One confirmed victim, the University of Nottingham, acknowledged a cybersecurity incident, and ShinyHunters later claimed to have published gigabytes of their stolen student data.
The impact of this vulnerability is critical. Successful exploitation gives attackers complete control of the PeopleSoft server, which often houses vast amounts of sensitive employee, financial, and student data. For a university, this could mean the exposure of student grades, financial aid information, and personal details for hundreds of thousands of individuals. For a corporation, it could expose payroll, HR records, and other critical business data. The consequences include massive data breaches, regulatory fines, and significant operational disruption.
Security teams may want to hunt for the following patterns to identify compromised systems:
MeshCentral.exepowershell.exe -enc ...Immediate action is required for all organizations running vulnerable PeopleSoft versions.
CVE-2026-35273. This is a critical Software Update.Beyond the immediate patch, long-term mitigation strategies include:
M1035 - Limit Access to Resource Over Network: Never expose administrative interfaces of enterprise applications like PeopleSoft directly to the internet. Access should be restricted via VPN or a secure bastion host.M1030 - Network Segmentation: Segment the network to isolate critical application servers like PeopleSoft from the general corporate network, limiting the potential for lateral movement.M1049 - Antivirus/Antimalware: Deploy EDR and antivirus solutions on all servers to detect and block post-exploitation tools like MeshCentral and malicious scripts.CISA adds PeopleSoft zero-day (CVE-2026-35273) to KEV catalog, mandating federal agency remediation. Over 100 orgs, mostly higher ed, breached by ShinyHunters.
The critical Oracle PeopleSoft zero-day, CVE-2026-35273, has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to remediate by June 15, 2026. A joint report by Mandiant and Google confirms ShinyHunters breached over 100 organizations, with 68% in the U.S. higher education sector, exploiting the 9.8 CVSS flaw between late May and early June 2026. This update provides a more precise victim count, a confirmed CVSS score, and highlights the increased urgency due to CISA's mandate.
NAIC confirms breach by ShinyHunters using PeopleSoft zero-day (CVE-2026-35273); CVSS 9.8 confirmed, exploitation active for two weeks.
The U.S. National Association of Insurance Commissioners (NAIC) has confirmed a breach by the ShinyHunters group, leveraging the critical Oracle PeopleSoft zero-day (CVE-2026-35273). The vulnerability's CVSS score is now confirmed at 9.8. Exploitation was active from May 27 to June 9, 2026, two weeks before Oracle's patch on June 10. The NAIC stated no PII was compromised, but public financial data was accessed. The FBI is investigating the broader campaign, which targeted over 100 organizations, expanding beyond the previously reported education sector to include regulatory bodies.
U.S. National Association of Insurance Commissioners (NAIC) breached by ShinyHunters using CVE-2026-35273. CVSS 9.8 confirmed, with active exploitation for two weeks before patch. FBI investigating broader campaign.
The U.S. National Association of Insurance Commissioners (NAIC) confirmed a breach by ShinyHunters, leveraging the critical CVE-2026-35273 in Oracle PeopleSoft. The vulnerability's CVSS score is confirmed at 9.8. Exploitation was active from May 27 to June 9, 2026, prior to Oracle's June 10 patch. Attackers accessed public financial data, though no PII was compromised at NAIC. The FBI is investigating this broader campaign, which targeted over 100 organizations. New hunting hints include monitoring web server logs for unusual requests and java.exe child processes, while detection methods emphasize vulnerability scanning and endpoint monitoring.
Oracle releases an out-of-band security alert and patch for CVE-2026-35273.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.