CVE-2026-35273, a critical vulnerability in Oracle PeopleSoft Enterprise PeopleTools with a CVSS score of 9.8, was exploited as a zero-day by the financially motivated group ShinyHunters — tracked by Mandiant as UNC6240 — from May 27 to June 9, 2026. Oracle released an emergency patch on June 10, 2026, the same day as its out-of-band advisory. By that point, Google Mandiant had already notified more than 100 organizations: 68% in higher education, though not all were necessarily compromised.
- The vulnerability resides in the PeopleSoft Environment Management Hub (PSEMHUB) component and enables unauthenticated RCE via SSRF, according to the NVD record and TrendAI Zero Day Initiative analyses.
- Active exploitation preceded the Oracle advisory by roughly two weeks, with CISA adding CVE-2026-35273 to the KEV catalog on June 12, 2026.
- ShinyHunters, a criminal group known for data theft and monetization, claimed 300+ compromised instances and published data from the University of Nottingham (~455,000 email addresses).
- The definitive fix arrived with the July 2026 Critical Patch Update.
The Mechanism: From SSRF to RCE via the Management Hub
The flaw affects the Updates Environment Management component, known as PSEMHUB, within PeopleTools versions 8.61 and 8.62. According to the CVE record published on NVD, the vulnerability is classified as SSRF (Server-Side Request Forgery, CWE-918) with a remote attack vector, low complexity, no privileges required, and no user interaction needed.
TrendAI Zero Day Initiative, credited with the original discovery, classified the mechanism as SSRF enabling remote code execution. The /PSEMHUB/hub endpoint and the /PSIGW/HttpListeningConnector connector allow an attacker to force the application server to issue attacker-controlled HTTP requests, opening the door to gadget chains that lead to arbitrary code execution.
Rapid7 confirmed the emergency patch was released the same day as the Oracle advisory, June 10, 2026. Charles Carmakal, Mandiant CTO, stated at the time — via LinkedIn, as reported by The Register — that "Oracle released mitigations. Patches should come soon," acknowledging the time pressure between emergency mitigations and the definitive fix.
The Campaign: Two Weeks of Silent Exploitation
According to Mandiant/Google Threat Intelligence Group analysis, cited by Tech Insider, malicious activity began on May 27, 2026, and continued through June 9. During this window the vulnerability was unknown to the public and unpatched: the technical definition of zero-day exploitation.
Identified attack infrastructure includes Python SimpleHTTPServer instances on port 8888, MeshCentral agents disguised as Azure binaries, and the C2 domain azurenetfiles.net. Lateral movement occurs via [victim]_fanout.sh scripts using SSH with hardcoded credentials against /etc/hosts entries. Data exfiltration uses zstd compression.
"While several organizations successfully blocked the activity or remediated the vulnerabilities, others experienced compromise, resulting in stolen data being published on the ShinyHunters Data Leak Website"
— Mandiant (via Tech Insider/TechCrunch)
The Victims: Higher Education as a Prime Target
Mandiant notified more than 100 potentially vulnerable or compromised organizations. 68% are in higher education, a concentration reflecting the historical prevalence of PeopleSoft in university ERP systems for student, finance, and HR management.
The University of Nottingham is the first publicly confirmed victim. The Have I Been Pwned database, run by Troy Hunt, recorded the exposure of approximately 455,000 unique email addresses. ShinyHunters directly claimed the breach in a statement to The Register: "University of Nottingham on our leak site is one of the first publicly confirmed incidents... We have only just started outreach to affected orgs."
The group claimed 300+ compromised PeopleSoft instances across 100+ organizations, according to The Next Web on June 11, 2026. This figure exceeds the number of Mandiant notifications, suggesting some organizations may have hosted multiple vulnerable instances.
What Changes
The attribution to UNC6240/ShinyHunters documents an expansion of the group's capabilities. Traditionally associated with SaaS credential theft and resale, the group demonstrated in this campaign the ability to exploit zero-day vulnerabilities in enterprise ERP systems.
Sources do not clarify whether ShinyHunters developed the zero-day research capability internally or acquired the vulnerability through third parties. This point remains undetermined and affects the assessment of threat sustainability: an end-to-end vulnerability research capability in Oracle ERP would represent a qualitative leap from the group's historical profile, but current sources do not allow conclusions on this front.
The definitive fix for CVE-2026-35273 was delivered in the July 2026 Critical Patch Update, as confirmed by TechTimes on July 21. The Oracle advisory also included CVE-2026-35278, a second RCE in the same PSEMHUB component, flagged as related but with no documented exploitation during the zero-day window.
The question of whether ShinyHunters will retain this zero-day capability or whether the incident represents a one-off event remains unanswered in available sources. Future risk assessment will depend on that determination, which cannot be made at this time.
Information has been verified against cited sources and is current as of publication.
Sources
- https://tech-insider.org/oracle-peoplesoft-zero-day-cve-2026-35273/
- https://www.techtimes.com/articles/318522/20260616/oracle-peoplesoft-zero-day-exploited-100-breaches-council-europe-deadline-falls-today.htm
- https://www.techtimes.com/articles/321140/20260721/peoplesoft-exploit-behind-100-breaches-gets-patched-oracles-record-july-cpu.htm
- https://thenextweb.com/news/oracle-peoplesoft-shinyhunters-zero-day-100-companies
- https://www.theregister.com/cyber-crime/2026/06/11/shinyhunters-claims-oracle-peoplesoft-0-day-hit-100-orgs/5254443
- https://nvd.nist.gov/vuln/detail/CVE-2026-35273
- https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html
- https://www.rapid7.com/blog/post/etr-active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273/
- https://www.securityweek.com/shinyhunters-claims-council-of-europe-hack/