Oracle released the Critical Patch Update on July 21, 2026, that definitively fixes CVE-2026-35278 and CVE-2026-35273, the vulnerability chain in PeopleSoft PeopleTools exploited by the ShinyHunters criminal group to compromise more than 300 servers belonging to over 100 organizations between May 27 and June 9. CISA's intervention with Binding Operational Directive 26-04, issued on June 10 before the full patch was even available, confirms the exceptional operational nature of the incident: a severity that surpassed simple vendor notification to enter the perimeter of federal emergency response.
- CVE-2026-35278 is a pre-authentication RCE in the PeopleTools 8.61 and 8.62 Performance Monitor component with CVSS 9.8: network access via HTTP, no credentials required
- CVE-2026-35273 is a privilege escalation in PeopleTools that received an out-of-cycle Security Alert on June 10, 2026, a signal Oracle reserves for vulnerabilities deemed too urgent to wait for the quarterly cycle
- Mandiant confirmed CVE-2026-35273 was exploited as a zero-day: attacks began before a fix existed
- The July 2026 CPU is cumulative and incorporates fixes from the May 28 and June 16 CSPUs; TechTimes reports 1,455 new vulnerabilities, while the Oracle advisory indicates 1,449 patches
Why CVSS 9.8 Trumped CVSS 9.9: The Metric That Matters Is Active Exposure
The July 2026 Oracle CPU also lists vulnerabilities with a CVSS 9.9 score, including CVE-2026-35263 in Database Server and CVE-2026-35268 in Identity Manager. None of them, however, generated a CISA Binding Operational Directive or a documented 13-day exposure window. A tenth of a point in theoretical score hides an operational abyss: CVE-2026-35278 and CVE-2026-35273 were already weapons in use against internet-connected targets, while the 9.9 flaws remained, at the time of release, potentialities not yet materialized in mass campaigns.
According to the NVD record for CVE-2026-35278, the attack vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H: network, low complexity, no privileges required, no user interaction. NVD annotates a CISA-ADP SSVC score for this CVE with exploitation:'none' as of June 17, an indicator that likely reflects the timing of public cataloging rather than an exhaustive assessment of observed activity, given Mandiant had already dated active exploitation between May 27 and June 9.
The Attack Chain: From Environment Management Hub to HR Database
The first phase exploits CVE-2026-35278 against the PeopleSoft Environment Management Hub, a component that accepts HTTP requests without authentication. As TechTimes reports: "No account. No password. Network access alone is sufficient." Initial access allows remote code execution with PeopleTools service privileges, insufficient for direct exfiltration but sufficient to trigger the second phase.
CVE-2026-35273, the privilege escalation, elevates control to full compromise of the PeopleSoft HCM database containing personnel records, payroll, and identifying data. The Oracle Security Alert of June 10 confirmed the flaw is "remotely exploitable without authentication" and "may result in remote code execution." The dossier does not specify the precise technical mechanism of the privilege escalation beyond these parameters.
The result is an end-to-end chain requiring no credential stuffing, phishing, or internal lateral movement: the attack surface is the PeopleSoft instance exposed on the HTTP port, typical of organizations enabling remote access for HR teams or payroll partners.
The Numbers of the Incident: From Moody Bible Institute to Nottingham
"By June 9, they had hit more than 300 institutions"
TechTimes documents 300 compromised servers in 13 days, with more than 100 organizations hit. Moody Bible Institute suffered exposure of 2.3 million personal records. SupplierShield, citing Mandiant analysis, names other victims: the University of Nottingham with approximately 450,000 students affected, Nissan with exposure of US/Canada/Mexico/Brazil personnel, and NAIC (National Association of Insurance Commissioners). SupplierShield emphasizes that "one provider's flaw exposed many downstream customers at the same time, which is the defining feature of software supply-chain and ICT concentration risk."
The ShinyHunters group, active since 2020 and specializing in data theft with subsequent sale or extortion, claimed its successes to BleepingComputer indicating "roughly 100 organizations," a figure consistent with the Mandiant estimate reported by SupplierShield. The dossier does not specify whether the data was fully published, sold, or if ransoms were paid.
The Federal Response: When the Vendor Is Not Enough
On June 10, 2026, 31 days before the definitive Critical Patch Update, CISA issued BOD 26-04 to accelerate remediation on exposed federal systems. The measure fits within the general framework of risk-based patch prioritization, but its specific timing — before the cumulative fix was available — indicates field intelligence judged the wait for Oracle's quarterly cycle unsustainable. The Oracle advisory of July 21 incorporates fixes from the May 28 and June 16 CSPUs, making the July CPU the first release that closes both phases of the chain in a single application.
Oracle recommended installing patches within 72 hours for exposed PeopleSoft instances. For organizations unable to patch immediately, the indicative guidance — reported by TechTimes — calls for restricting HTTP access to the Environment Management Hub to trusted IP ranges. This measure reduces the attack surface but does not eliminate the risk of lateral movement from other compromised assets within authorized ranges.
What to Do Now
- Verify the presence of PeopleTools versions 8.61 or 8.62 in internet-exposed environments, with particular attention to the enabled Environment Management Hub
- Apply the July 2026 CPU within 72 hours for PeopleSoft HCM/PeopleTools instances with remote access; the patch is cumulative and replaces previous CSPUs
- If patching is not immediately executable, restrict HTTP access to the Performance Monitor/Environment Management Hub component to trusted IP addresses, monitoring logs for anomalous connections
- Assess the need for an independent compromise assessment for instances exposed during the May 27–June 9, 2026 period, given Mandiant's confirmation of zero-day exploitation
The Severity Paradox: When Operational Risk Overwrites Theoretical Score
The 2026 PeopleSoft incident offers a case study on the distance between risk assessment and risk management. The CVSS system is designed to measure the intrinsic severity of a vulnerability, not the likelihood of exploitation nor the systemic impact on a specific organization's portfolio. A Database Server flaw with changed scope and a 9.9 score is theoretically more severe than a 9.8 RCE with unchanged scope; but if the first is not explosive in the field and the second has already generated hundreds of concrete compromises, operational priority inverts.
For third-party risk managers, DORA and NIS2 compliance officers, and cyber insurance teams, the episode highlights a form of concentrated risk that traditional frameworks struggle to capture: dependence on a single ERP vendor that, at the moment of the flaw, transforms a software defect into a sector-wide event. The frequency with which ShinyHunters converted the vulnerability into confirmed access suggests weaponization was stable and repeatable, not a proof-of-concept adapted case by case.
Sources
- https://www.techtimes.com/articles/321140/20260721/peoplesoft-exploit-behind-100-breaches-gets-patched-oracles-record-july-cpu.htm
- https://www.oracle.com/security-alerts/cpujul2026.html
- https://www.suppliershield.com/post/oracle-peoplesoft-zero-day-cve-2026-35273-breaches-100-organisations
- https://threat-modeling.com/oracle-july-2026-critical-patch-update/
- https://nvd.nist.gov/vuln/detail/CVE-2026-35263
- https://nvd.nist.gov/vuln/detail/CVE-2026-35278
- https://nvd.nist.gov/vuln/detail/CVE-2026-35268
- https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- https://support.oracle.com/
Information verified against cited sources and current as of publication.