XOOMAR
Enterprise server shielded from zero-day data theft attacks in a dark cybersecurity scene.
CybersecurityJune 11, 2026· 5 min read· By XOOMAR Insights Team

No Patch Yet as PeopleSoft Zero-Day Opens RCE Door

Share
Updated on June 11, 2026

Oracle's emergency response is a mitigation, not the full patch administrators want, and it lands after a PeopleSoft zero-day was linked to live ShinyHunters data theft attacks.

XOOMAR Intelligence

Analyst Take

60/ 100
Moderate
4 sources analyzedLow confidenceTrend20Freshness94Source Trust88Factual Grounding94Signal Cluster20

The flaw, tracked as CVE-2026-35273, sits in Oracle PeopleSoft PeopleTools and allows unauthenticated remote code execution, according to BleepingComputer. Oracle assigned it a CVSS base score of 9.8 and said affected customers should act now while a patch is still pending.

Oracle issues mitigations, not a full patch, for CVE-2026-35273

Oracle said the vulnerability affects PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62. PeopleSoft Enterprise Applications customers may also be affected.

The company’s advisory is blunt about the technical risk.

"This vulnerability is remotely exploitable without authentication. If successfully exploited, this vulnerability may result in remote code execution."

That combination is the nightmare version of an enterprise software bug. No valid username. No stolen password required. If the system is exposed and vulnerable, the attacker may be able to run code remotely.

Oracle has released emergency mitigations for the flaw. BleepingComputer reports that a patch is coming soon, which means administrators are operating in the uncomfortable gap between public disclosure and a complete fix.

The tension is clear:

  • Expected: A critical enterprise zero-day gets a patch before widespread public detail.
  • Reality: Oracle has issued mitigations while reports tie the flaw to active data theft.
  • Immediate risk: Exposed PeopleSoft systems now become urgent review targets.
  • Unknown: Oracle has not publicly confirmed exploitation in its advisory.

BleepingComputer said it first reported that the ShinyHunters extortion gang was exploiting a PeopleSoft zero-day to breach instances and steal data. It later learned that the exploited flaw is CVE-2026-35273.

Charles Carmakal, CTO at Mandiant, Google Cloud, also confirmed on LinkedIn that the vulnerability is being actively exploited and said Oracle had released mitigations.


Unauthenticated PeopleSoft RCE puts HR, payroll, finance and campus systems in the blast radius

PeopleSoft matters because it sits close to an organization’s most sensitive operational data. SecurityWeek describes it as an integrated ERP suite used by large organizations for HR, payroll, finance, supply chain and campus operations.

That makes this zero-day attractive to a data theft crew. A compromised PeopleSoft environment can contain employee records, payroll information, financial workflows, student data or internal administrative records, depending on how an organization uses it.

ShinyHunters claimed to BleepingComputer that it used a "gadget chain" of old and zero-day flaws to breach PeopleSoft instances. The group also claimed it stole data from 300 instances across more than 100 organizations.

Oracle has not said in its public advisory that CVE-2026-35273 is being exploited in the wild. That silence matters, but it doesn’t erase the reporting from BleepingComputer or the confirmation from Carmakal.

This is where enterprise risk gets ugly. The official vendor language says mitigation. The threat reporting says active exploitation. Security teams have to respond to the second reality, not wait for the first one to get more detailed.

For readers tracking adjacent vulnerability coverage, XOOMAR has also covered 4-Hour BitLocker Zero-Day Opens Windows SYSTEM Shell and Langflow Flaw Lets Hackers Write Files on AI Servers. The common thread is exposure speed: once a practical path exists, defenders lose time fast.

BleepingComputer describes ShinyHunters as a threat actor known for breaching cloud SaaS instances, CRMs and enterprise platforms that store large volumes of corporate data. After access, the group downloads data and demands payment to prevent public leaks.

The group has been linked to attacks targeting SnowFlake, Salesforce and third-party integration providers over the past year, according to the same report.

That history matters because the PeopleSoft activity appears to follow the same commercial logic. The target isn’t just the server. It’s the data behind the server.

BleepingComputer reported Tuesday that Oracle PeopleSoft was hit in a wave of data theft attacks that left ransom notes purportedly from ShinyHunters. ShinyHunters later confirmed to BleepingComputer that it was behind the attacks.

SecurityWeek reported that the education sector was hit hardest and that the University of Nottingham is one of the victims. The university has confirmed it suffered a significant data breach, according to SecurityWeek.

A researcher identified as "Michael R" found exposed online directories containing attack-related tooling and shared IP addresses used in the attacks. BleepingComputer advised PeopleSoft customers to check logs for connections from those IPs:

142.11.200[.]186
142.11.200[.]187
142.11.200[.]188
142.11.200[.]189
142.11.200[.]190
108.174.202[.]99
176.120.22[.]24

That is the most concrete hunting lead in the public reporting so far.


PeopleSoft admins have a narrow window before copycat pressure builds

The immediate action is not subtle. Organizations running Oracle PeopleSoft should review Oracle’s advisory, apply the emergency mitigations and check whether they run affected PeopleTools 8.61 or 8.62 deployments.

BleepingComputer specifically advises customers to analyze logs for connections from the listed IP addresses to determine whether they were targeted. That should be the starting point, not the finish line.

Oracle has not provided full public technical detail in the advisory. That restraint is normal for a live critical flaw because more detail can help defenders and attackers at the same time.

The practical question now is whether mitigation closes enough of the attack path until Oracle ships the patch. If exposed PeopleSoft instances remain reachable and unmitigated, ShinyHunters may not be the only actor interested for long.

BleepingComputer said it contacted Oracle with questions about the vulnerability and the attacks but had not received a response. SecurityWeek also said Oracle had not responded by the time of writing.

The next signals to watch are specific: Oracle’s full patch timing, any new technical indicators, confirmation of additional victims and whether other threat groups start using CVE-2026-35273 now that the flaw is public. For now, the safest assumption for exposed PeopleSoft systems is that mitigation is urgent and log review can’t wait.

Impact Analysis

  • The flaw allows unauthenticated remote code execution in affected PeopleSoft PeopleTools systems.
  • Oracle has released mitigations, but a full patch is still pending.
  • Reported exploitation tied to ShinyHunters means exposed enterprise systems need immediate review.

Oracle PeopleSoft Response Status

ItemStatusImplication
Emergency mitigationsReleasedAdministrators have temporary defenses to apply immediately.
Full patchPendingSystems remain in a higher-risk window until a complete fix is available.
ExploitationReported by BleepingComputerShinyHunters-linked data theft attacks raise urgency for exposed PeopleSoft instances.

Severity of CVE-2026-35273

CVSS base score
CVSS9.8
XOOMAR

Written by

XOOMAR Insights Team

Research and Editorial Desk

The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.

Related Articles

Dark cybersecurity scene with shields, locks, servers, and breached HR data around a corporate building.Cybersecurity

Estée Lauder Data Breach Hid for 10 Months in Oracle

Attackers stole sensitive HR data through Oracle E-Business, and Estée Lauder took 10 months to confirm what was exposed.

Jul 21, 20267 min
Secure data center with shields and locks protecting patched enterprise software vulnerabilitiesCybersecurity

10/10 Adobe ColdFusion Vulnerabilities Threaten Servers

Adobe patched seven 10/10 flaws in ColdFusion and Campaign Classic that could let attackers run code on exposed systems.

Jul 1, 20264 min
Dark cybersecurity scene with broken shields, locks, data shards, and ransomware breach imagery.Cybersecurity

Worst Breaches of 2026 Put Millions in Hackers' Hands

The year's worst breaches exposed students, cloud keys, devices, and Social Security data, turning stolen records into real-world disruption.

Jul 11, 20268 min
Hospital IT breach scene with protected medical devices, servers, shields, locks, and data streams.Cybersecurity

3.8 Million Caught in Medtronic Data Breach Fallout

Medtronic says devices stayed safe, but 3.8 million people had personal and medical data exposed through corporate IT.

Jul 3, 202611 min
Cyberattack on protected enterprise payments servers with shields, locks, code matrix, and honeypot decoys.Cybersecurity

Attackers Pounce on Oracle Payments CVE-2026-46817

Attackers hit Oracle Payments decoys six weeks after the CVE-2026-46817 patch, before public exploit code surfaced.

Jun 30, 20265 min
Protesters near a Libyan energy complex as pipelines and city blackout lights suggest growing grid crisis.Global Trends

Stormed Gas Lines Push Libya Energy Complex Crisis to Brink

Protesters shut gas lines at Mellitah, turning Libya's power outages into a direct threat to Tripoli's grip on the grid.

Jul 28, 20268 min
Ebola response in Congo with health workers, community tension, and a faint global map overlay.Global Trends

10-Week Congo Ebola Outbreak Races Toward Worst-Ever Record

Congo’s Ebola outbreak hit 3,262 cases in 10 weeks, exposing a response strained by violence, unpaid workers and mistrust.

Jul 28, 20267 min
Engineers shift between futuristic chip labs amid glowing wafers, servers, and semiconductor workstations.Technology

Samsung Chip Workers Plot Exit as SK Hynix Pays $476K

Samsung's foundry talent problem is now a pay war, with SK Hynix bonuses making its HBM gap harder to close.

Jul 28, 20268 min
Japan earthquake aftermath with responders, sheltering residents, cracked roads, coastline, and global map overlay.Global Trends

150,000 Told to Evacuate as Japan Earthquake Injures Dozens

A 7.1 Japan earthquake injured dozens, triggered brief tsunami fears, and pushed 150,000 people toward shelters.

Jul 28, 20265 min
Wide establishing shot of a neutral orbital defense hub at the Earth-Moon Lagrange point, ring-shaped station with reflective shield panels, tiny maintenance drones, Earth glowing blue-white below with faint auroras and satellite constellations, hopeful bFuture Fiction

The Ceasefire Engineer of Lagrange Market

In 2069, nations no longer send armies across borders; they release swarms, exploits, orbital shields, and autonomous legal agents into a constantly contested battlespace called the Quiet Front. Naya Voss, a civilian conflict-auditor stationed at a neutral space-based defense hub, discovers that an escalating machine-to-machine war over water rights is being driven not by hatred, but by incompatible definitions of surrender.

Jul 28, 202615 min

Don't miss the signal

Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.

Free forever. No spam. Unsubscribe anytime.