ShinyHunters Exploits Oracle PeopleSoft Zero‑Day (CVE‑2026‑35273) After Patch Workarounds
What Happened — Mandiant confirmed that the ShinyHunters group has resumed active exploitation of Oracle PeopleSoft’s CVE‑2026‑35273. The attackers are targeting organizations that applied only the vendor‑issued workarounds instead of the full patch, deploying web shells on dozens of systems worldwide. The campaign has already resulted in confirmed data exfiltration and extortion threats across government, education, healthcare and other sectors.
Why It Matters for Trust & Control Assurance
- Demonstrates a failure in the patch‑management and vulnerability remediation control objective – a single control that satisfies many framework requirements (NIST CSF 2.0, ISO 27001, etc.).
- Highlights the need for continuous evidence collection that a patch is truly applied, not just a temporary workaround.
- Shows how a robust control‑mapping program can surface gaps quickly and provide defensible audit trails.
Who Is Affected – Government agencies, higher‑education institutions, healthcare providers, technology and IT‑services firms, plus organizations in agriculture and transportation that run Oracle PeopleSoft.
Recommended Actions
- Verify that the official Oracle PeopleSoft patch for CVE‑2026‑35273 is installed on every instance.
- If patching is delayed, enforce compensating controls (network segmentation, strict access monitoring) and document them as evidence.
- Review PeopleSoft database and application logs for anomalous queries, web‑shell artifacts, or unexpected configuration changes.
- Update your control‑mapping repository to reflect the remediation status of the relevant control objective.
Technical Notes – CVE‑2026‑35273 is a remote code execution flaw in Oracle PeopleSoft that allows unauthenticated attackers to upload web shells and execute arbitrary commands. The vulnerability was disclosed in June 2026; Oracle released a patch on 10 June 2026. ShinyHunters leveraged the window between disclosure and patch, and now targets systems that only applied the interim workarounds. Source: The Record