Oracle mitigates PeopleSoft zero-day exploited in data theft attacks

Oracle mitigates PeopleSoft zero-day exploited in data theft attacks β€” Cybersecurity | Versia.media

Oracle has issued a warning regarding a critical zero-day vulnerability in its PeopleSoft Suite, designated as CVE-2026-35273, which enables unauthenticated remote code execution. This flaw is currently being actively exploited in data theft campaigns carried out by the ShinyHunter group.

The vulnerability resides within Oracle PeopleSoft PeopleTools and carries a CVSS base score of 9.8.

"This Security Alert addresses vulnerability CVE-2026-35273 in Oracle PeopleSoft PeopleTools. Oracle PeopleSoft Enterprise Applications customers may also be affected by this vulnerability," states a new advisory from Oracle.

"This vulnerability is remotely exploitable without authentication. If successfully exploited, this vulnerability may result in remote code execution."

Oracle has confirmed that the zero-day flaw impacts PeopleSoft Enterprise PeopleTools, versions 8.61 and 8.62, and has released emergency mitigations to address the issue, with a patch expected to be available soon.

Zero-day exploited in ShinyHunter data theft attacks

Although Oracle has not explicitly stated that this vulnerability is being actively exploited, its disclosure follows a report by BleepingComputer indicating that the ShinyHunters extortion gang was leveraging a PeopleSoft zero-day to breach instances and steal data.

BleepingComputer has since confirmed that this is the zero-day used in those attacks.

On Tuesday, BleepingComputer discovered that Oracle PeopleSoft was targeted in a series of data theft attacks that left ransom notes allegedly from the ShinyHunters extortion gang.

ShinyHunters is a well-known threat actor that frequently breaches cloud SaaS instances, CRMs, and enterprise platforms hosting large volumes of corporate data. After gaining access to an instance, they download the data and demand a ransom to prevent its public disclosure.

The group has been linked to several high-profile attacks targeting SnowFlake, Salesforce, and third-party integration providers over the past year.

ShinyHunters confirmed to BleepingComputer that they are behind these attacks, claiming to use a "gadget chain" of both old and zero-day flaws to breach PeopleSoft instances.

Using this flaw, the threat actor allegedly stole data from 300 instances belonging to over 100 organizations.

Cybersecurity researcher "Michael R" discovered several exposed online directories containing attack-related tools and shared the following IP addresses used in the attacks.

Targeting the education sector

Mandiant released a report confirming that threat actors exploited the Oracle PeopleSoft CVE-2026-35273 vulnerability as a zero-day, primarily targeting organizations in the education sector.

"Upon becoming aware of active scanning and exploitation, we initiated notifications to over 100 global organizations whose IP addresses correlated with potentially vulnerable endpoints," Mandiant reported.

"Most of these organizations were based in the United States, and 68 percent operated within the higher education sector."

Mandiant's report also provided additional technical details about the attacks, noting that the threat actors used exposed staging servers to host HTTP services and employed custom MeshCentral remote management agents to communicate with attacker-controlled infrastructure disguised as Microsoft Azure services.

The researchers stated that the threat actors conducted reconnaissance on compromised instances, mapped PeopleSoft and WebLogic configurations, and used scripts to move laterally across internal systems using stolen or hardcoded credentials.

Mandiant also indicated that the attackers compressed exfiltrated data and ultimately connected to a server at 176.120.22.24, which is linked to the public ShinyHunters data leak site, helping connect the activity to the extortion group.

As part of its guidance, Mandiant advised organizations to restrict access to vulnerable PeopleSoft endpoints, review logs for suspicious requests targeting /PSEMHUB/ and /PSIGW/HttpListeningConnector, and inspect servers for signs of compromise, including:

Unexpected .jsp webshell files in WebLogic application directories

Unauthorized files or binaries staged in PSEMHUB transaction folders

Suspicious directories such as logs, persistantstorage, or scratchpad

Recently modified XML files that could be used to maintain persistence or trigger remote code execution after a restart

ShinyHunters recently targeted the education sector in a major cyberattack on Instructure Canvas, which allowed them to steal 280 million data records for students, teachers, and staff. Instructure later paid a ransom to prevent the leaking of the stolen data.

BleepingComputer has contacted Oracle with questions about the vulnerability and the attacks but has not yet received a response.

Test every layer before attackers do

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Related Articles:

Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks

Ivanti warns of new actively exploited MobileIron zero-day bug

Check Point links VPN zero-day attacks to Qilin ransomware gang

CISA flags two-year-old Oracle flaw as actively exploited in attacks

Google fixes one actively exploited Android zero-day, 124 flaws

← Cybersecurity