Oracle has issued an out-of-band security alert and patch for a critical zero-day vulnerability, CVE-2026-35273, affecting its PeopleSoft PeopleTools enterprise software. The flaw is a remotely exploitable, unauthenticated vulnerability that can lead to remote code execution (RCE), posing a severe risk to affected organizations. The emergency action was prompted by active in-the-wild exploitation attributed to the ShinyHunters extortion group. The group claims to have breached over 100 organizations, particularly in the education sector, by chaining this zero-day with other vulnerabilities to steal large volumes of data for extortion campaigns. Organizations using PeopleSoft PeopleTools versions 8.61 and 8.62 are urged to apply the patch immediately.
CVE-2026-35273The vulnerability allows a remote attacker, without needing any credentials, to execute arbitrary code on a vulnerable PeopleSoft server. This effectively gives the attacker full control over the server, allowing them to steal data, install additional malware, or pivot deeper into the victim's network.
The vulnerability is a zero-day that is confirmed to be actively exploited in the wild. The ShinyHunters threat group is using the flaw as part of a "gadget chain"—a sequence of vulnerabilities—to compromise PeopleSoft servers. Mandiant's CTO has publicly confirmed the active attacks. ShinyHunters claims to have breached over 300 instances at more than 100 organizations, with a heavy focus on universities.
One confirmed victim, the University of Nottingham, acknowledged a cybersecurity incident, and ShinyHunters later claimed to have published gigabytes of their stolen student data.
The impact of this vulnerability is critical. Successful exploitation gives attackers complete control of the PeopleSoft server, which often houses vast amounts of sensitive employee, financial, and student data. For a university, this could mean the exposure of student grades, financial aid information, and personal details for hundreds of thousands of individuals. For a corporation, it could expose payroll, HR records, and other critical business data. The consequences include massive data breaches, regulatory fines, and significant operational disruption.
Security teams may want to hunt for the following patterns to identify compromised systems:
MeshCentral.exepowershell.exe -enc ...Immediate action is required for all organizations running vulnerable PeopleSoft versions.
CVE-2026-35273. This is a critical Software Update.Beyond the immediate patch, long-term mitigation strategies include:
M1035 - Limit Access to Resource Over Network: Never expose administrative interfaces of enterprise applications like PeopleSoft directly to the internet. Access should be restricted via VPN or a secure bastion host.M1030 - Network Segmentation: Segment the network to isolate critical application servers like PeopleSoft from the general corporate network, limiting the potential for lateral movement.M1049 - Antivirus/Antimalware: Deploy EDR and antivirus solutions on all servers to detect and block post-exploitation tools like MeshCentral and malicious scripts.The most critical action is to apply the emergency patch from Oracle immediately.
Do not expose PeopleSoft administrative interfaces to the public internet. Restrict access to a trusted set of internal IPs.
Oracle releases an out-of-band security alert and patch for CVE-2026-35273.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.