ShinyHunters Exploit Oracle PeopleSoft Zero-Day CVE-2026-35273

An unauthenticated RCE flaw in Oracle PeopleSoft was exploited for nearly two weeks by ShinyHunters before Oracle's June 10 advisory, with 68% of victims in higher education.

ShinyHunters Exploit Oracle PeopleSoft Zero-Day CVE-2026-35273

A previously unknown remote code execution flaw in Oracle PeopleSoft has been exploited as a zero-day for nearly two weeks, exposing universities and other large institutions to data theft and extortion from the cybercrime crew known as ShinyHunters.

What the bug does

The vulnerability, tracked as CVE-2026-35273, is an unauthenticated remote code execution flaw in Oracle PeopleSoft Enterprise PeopleTools with a CVSS score of 9.8. The bug sits in the Environment Management Hub (PSEMHUB), and an attacker needs nothing more than network access over HTTP to take full control of the server. Oracle lists PeopleTools 8.61 and 8.62 as affected and says earlier, unsupported versions are likely vulnerable too.

Exploited as a zero-day

Google's Mandiant and the Google Threat Intelligence Group attribute the campaign to a cluster they track as UNC6240, better known as ShinyHunters. The intrusions ran between May 27 and June 9, 2026, before Oracle published its advisory on June 10, meaning the bug was a true zero-day the entire time. Mandiant CTO Charles Carmakal publicly confirmed exploitation in the wild.

Enterprise data theft and extortion campaign

Universities take the brunt

Mandiant notified more than 100 organizations whose internet-facing endpoints matched the attackers' targeting. Sixty-eight percent of the victims were in higher education, most of them U.S. universities. The University of Nottingham has confirmed a breach in which Have I Been Pwned counted roughly 455,000 unique email addresses, with passport numbers, addresses and other sensitive fields included in the stolen set.

Mitigation guidance

Until the patch is applied, Oracle recommends disabling the Environment Management Hub on multi-server deployments or removing the PSEMHUB application entirely on single-server setups. Defenders should also block external access to /PSEMHUB/* and /PSIGW/HttpListeningConnector at the perimeter, and hunt for new .jsp files and modified XML metadata under the PSEMHUB web root. The campaign follows a string of recent ShinyHunters operations, including their Carnival data breach, and tracks alongside the broader push toward CISA's risk-based vulnerability management directive. Enterprise teams already moving on the Chrome V8 zero-day should fold PSEMHUB into the same emergency window.

Reporting based on coverage from The Hacker News, Google Cloud Threat Intelligence, SecurityWeek and Oracle's June 10 advisory.

Category: Cyber Security

Tags: Google Cybersecurity

Related Articles