Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

ShinyHunters Exploits Oracle PeopleSoft Zero‑Day (CVE‑2026‑35273) After Patch Workarounds

Mandiant reports that the ShinyHunters group has resumed exploitation of Oracle PeopleSoft’s CVE‑2026‑35273, targeting organizations that relied on workarounds instead of the official patch. The campaign has deployed web shells across government, education, healthcare and other sectors, leading to confirmed data exfiltration and extortion threats. This underscores the need for robust patch‑management and continuous control‑assurance evidence.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 therecord.media
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
4 sector(s)
✅
Actions
4 recommended
📰
Source
therecord.media

ShinyHunters Exploits Oracle PeopleSoft Zero‑Day (CVE‑2026‑35273) After Patch Workarounds

What Happened — Mandiant confirmed that the ShinyHunters group has resumed active exploitation of Oracle PeopleSoft’s CVE‑2026‑35273. The attackers are targeting organizations that applied only the vendor‑issued workarounds instead of the full patch, deploying web shells on dozens of systems worldwide. The campaign has already resulted in confirmed data exfiltration and extortion threats across government, education, healthcare and other sectors.

Why It Matters for Trust & Control Assurance

  • Demonstrates a failure in the patch‑management and vulnerability remediation control objective – a single control that satisfies many framework requirements (NIST CSF 2.0, ISO 27001, etc.).
  • Highlights the need for continuous evidence collection that a patch is truly applied, not just a temporary workaround.
  • Shows how a robust control‑mapping program can surface gaps quickly and provide defensible audit trails.

Who Is Affected – Government agencies, higher‑education institutions, healthcare providers, technology and IT‑services firms, plus organizations in agriculture and transportation that run Oracle PeopleSoft.

Recommended Actions

  • Verify that the official Oracle PeopleSoft patch for CVE‑2026‑35273 is installed on every instance.
  • If patching is delayed, enforce compensating controls (network segmentation, strict access monitoring) and document them as evidence.
  • Review PeopleSoft database and application logs for anomalous queries, web‑shell artifacts, or unexpected configuration changes.
  • Update your control‑mapping repository to reflect the remediation status of the relevant control objective.

Technical Notes – CVE‑2026‑35273 is a remote code execution flaw in Oracle PeopleSoft that allows unauthenticated attackers to upload web shells and execute arbitrary commands. The vulnerability was disclosed in June 2026; Oracle released a patch on 10 June 2026. ShinyHunters leveraged the window between disclosure and patch, and now targets systems that only applied the interim workarounds. Source: The Record

📰 Original Source
https://therecord.media/shinyhunters-cyberattacks-oracle-mandiant ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →