ShinyHunters Exploits Oracle PeopleSoft Zero-Day CVE-2026-35273 in Mass Hacking Campaign
Image: Zamin.uz

ShinyHunters Exploits Oracle PeopleSoft Zero-Day CVE-2026-35273 in Mass Hacking Campaign

10 June, 2026.Crime.25 sources

ShinyHunters exploited CVE-2026-35273 in Oracle PeopleSoft, breaching 100+ organizations, mostly universities. Oracle issued an out-of-band advisory and patch for the unauthenticated RCE flaw.

25 outlets3 divides3 facts unevenly covered

Beat 1 · The verdict

Whether Oracle has released a patch/fix

Full story

Zero-day used on PeopleSoft

Oracle PeopleSoft PeopleTools servers were targeted in the wild after a zero-day vulnerability, tracked as CVE-2026-35273, was exploited in a mass-hacking campaign linked to ShinyHunters.

CVE-2026-35273) in Oracle PeopleSoft PeopleTools is being exploited in the wild

Help Net SecurityHelp Net Security

Mandiant CTO Charles Carmakal warned that the flaw is remotely exploitable without authentication and may result in remote code execution, affecting PeopleSoft PeopleTools versions 8.61 and 8.62.

Image from Ars Technica
Ars TechnicaArs Technica

Mandiant and the Google Threat Intelligence Group confirmed that ShinyHunters (UNC6240) targeted Oracle PeopleSoft application infrastructure between May 27, 2026 and June 9, 2026, and said the activity “is consistent” with exploitation of CVE-2026-35273.

Oracle’s advisory said the vulnerability is remotely exploitable without authentication and “may result in remote code execution,” while TechCrunch reported Oracle had not released a patch “at the time of writing.”

Higher education hit, data leaked

Mandiant said it notified more than “100 global organizations,” most of them in the United States, and TechCrunch reported that about two-thirds of those organizations are in higher education.

The campaign’s impact included stolen data being published on the ShinyHunters [Data Leak Website], and Mandiant wrote that “others experienced compromise, resulting in stolen data being published.”

Image from BleepingComputer
BleepingComputerBleepingComputer

The University of Nottingham confirmed it suffered a cybersecurity incident and that it notified affected students and alumni directly, while Cybersecurity Dive reported the university said a “significant amount of data” in its student records was compromised.

Cybersecurity Dive added that the flaw was added to CISA’s Known Exploited Vulnerabilities catalog and confirmed it has been used in ransomware attacks, and it said federal civilian agencies have until Monday to remediate the vulnerability.

Mitigations and ongoing extortion

Oracle urged customers to apply mitigations and take “immediate action” to reduce exposure, including disabling the Environment Management Hub service in Multi-Server configurations or removing the PSEM hub in Single-Server configurations.

This vulnerability is remotely exploitable without authentication

TechRadarTechRadar

If organizations could not disable the EMHub service, Oracle guidance described blocking external access to /PSEMHUB/* and /PSIGW/HttpListeningConnector at the network perimeter or firewall level, and Mandiant warned that WAF body-inspection rules alone are not enough.

Researchers tied to Mandiant and the Google Threat Intelligence Group said the attackers used customized MeshCentral agents disguised as Microsoft Azure services, and the campaign relied on remote code execution without authentication to take over exposed systems.

CyberScoop reported that Charles Carmakal said, “This campaign is still active,” and it described extortions being sent as recently as that Thursday evening, with the implication that more victims beyond Google’s visibility may be impacted.

Story read · 25 outlets · 3 disagreements · 3 facts unevenly covered

The divide · 1 of 3

Whether Oracle has released a patch/fix

Conflicting reporting affects urgency and what defenses teams can apply.

Coverage map

How each outlet frames it

Every outlet we compared, the headline it ran, and a link to the original article.

Western Mainstream

Ars Technica
Ars Technica

PeopleSoft 0-day affecting hundreds of organizations steals gigabytes of data

12 June, 2026

TechCrunch
TechCrunch

Cybercriminals claim breach of Oracle PeopleSoft servers at 100-plus organizations

10 June, 2026

TechCrunch
TechCrunch

Oracle warns of security bug that hackers abused to breach 100+ companies

11 June, 2026

TechRadar
TechRadar

Oracle warns of critical PeopleSoft attack affecting hundreds of customers

12 June, 2026

The Hacker News
The Hacker News

ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities

11 June, 2026

Other

BleepingComputer
BleepingComputer

Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks

10 June, 2026

Computer Weekly
Computer Weekly

Oracle fixes PeopleSoft flaw exploited by ShinyHunters

12 June, 2026

CSO Online
CSO Online

Oracle PeopleSoft zero‑day fuels ShinyHunters extortion spree

12 June, 2026

CyberScoop
CyberScoop

ShinyHunters is actively extorting universities after exploiting an unpatched Oracle flaw

12 June, 2026

Cybersecurity Dive
Cybersecurity Dive

ShinyHunters linked to exploitation of critical flaw in Oracle PeopleSoft

12 June, 2026

Dark Reading
Dark Reading

ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed

12 June, 2026

Hackread
Hackread

ShinyHunters Target Universities in Oracle PeopleSoft Zero-Day Attack

12 June, 2026

Help Net Security
Help Net Security

Oracle PeopleSoft servers under attack, Oracle pushes out-of-band security alert

11 June, 2026

Oracle Blogs
Oracle Blogs

Security Alert CVE-2026-35273 Released

11 June, 2026

Rescana
Rescana

Oracle PeopleSoft PeopleTools Zero-Day (CVE-2026-35273) Actively Exploited: Urgent Patch Required to Prevent Ransomware and Data Breaches

11 June, 2026

Security Boulevard
Security Boulevard

Oracle PeopleSoft Servers Hacked in ShinyHunters Data Theft Attacks

11 June, 2026

SecurityWeek
SecurityWeek

Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks

11 June, 2026

SecurityWeek
SecurityWeek

Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters

12 June, 2026

Technology Org
Technology Org

ShinyHunters Hackers Exploit Unpatched Oracle Bug to Steal Data From 100+ Companies

12 June, 2026

Techzine Global
Techzine Global

ShinyHunters targets Oracle PeopleSoft

11 June, 2026

The Register
The Register

ShinyHunters hacked 100+ orgs by exploiting an Oracle PeopleSoft 0-day

11 June, 2026

Zamin.uz
Zamin.uz

Hackers breach Oracle PeopleSoft servers of over 100 organizations

10 June, 2026

Western Alternative

Crypto Briefing
Crypto Briefing

Oracle PeopleSoft servers targeted in data theft attacks linked to ShinyHunters

10 June, 2026

The Tech Buzz
The Tech Buzz

ShinyHunters Claims Breach of 100+ Oracle PeopleSoft Servers

10 June, 2026

Local Western

mezha.net
mezha.net

ShinyHunters breached Oracle PeopleSoft at 100+ organizations, exposing student and staff data

10 June, 2026

NewsCord Digest

Get every Crime story like this one, in one email

Daily or weekly, only the topics you follow, each with the difference our analysis found across the outlets covering it.

Set up your digest

More on Crime