HomeIntelligenceBrief
BREACH BRIEF 🔴 Critical Breach

ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Compromise 100+ Universities

ShinyHunters leveraged an unauthenticated remote‑code‑execution flaw in Oracle PeopleSoft (CVE‑2026‑35273) to breach over 100 organizations, primarily U.S. universities, before a vendor patch was released. The zero‑day campaign underscores the need for rapid vendor patch monitoring and robust third‑party risk controls.

Verisq™ Intelligence · 📅 June 12, 2026 · 📰 securityaffairs.com
🔴
Severity
Critical
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
securityaffairs.com

ShinyHunters Exploits Oracle PeopleSoft Zero‑Day (CVE‑2026‑35273) to Compromise 100+ Universities

What Happened — ShinyHunters (UNC6240) leveraged a critical, unauthenticated remote‑code‑execution flaw in Oracle PeopleSoft’s Environment Management component (CVE‑2026‑35273, CVSS 9.8) to infiltrate more than 100 organizations, 68 % of which were U.S. universities, before Oracle released an advisory. The campaign ran from 27 May to 9 June 2026, effectively a zero‑day attack.

Why It Matters for TPRM

  • Critical PeopleSoft vulnerability can affect any third‑party ERP/HR system used by education institutions and other enterprises.
  • Exploitation occurred before a patch existed, highlighting the risk of undisclosed zero‑days in vendor products.
  • The extortion‑focused campaign demonstrates that a compromised vendor can become a conduit for data theft and ransomware‑style pressure on downstream customers.

Who Is Affected — Higher‑education institutions, research labs, and any organization running Oracle PeopleSoft (PeopleTools 8.61/8.62 or earlier).

Recommended Actions

  • Verify whether your organization uses Oracle PeopleSoft; if so, confirm version and apply the June 10 2026 patch immediately.
  • Review third‑party risk contracts for clauses on zero‑day exposure and vendor patch timelines.
  • Conduct network segmentation and restrict access to the Environment Management Hub endpoint.
  • Monitor for Indicators of Compromise (IoCs) published by Mandiant and Google Threat Intelligence.

Technical Notes — The flaw is a remote code execution vulnerability in the Environment Management Hub (PSEMHUB) that requires only network connectivity—no authentication or user interaction. Exploited binaries were disguised as Azure services and delivered via a staging infrastructure exposing .bash_history files. CVE‑2026‑35273 scores 9.8/10 (CVSS). Source: SecurityAffairs

📰 Original Source
https://securityaffairs.com/193543/cyber-crime/oracle-peoplesoft-rce-flaw-used-as-zero-day-in-ongoing-shinyhunters-campaign.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →