ShinyHunters Claims a Second PeopleSoft Zero-Day, and Oracle Has Said Nothing

A known criminal group says it used an unpatched Oracle flaw to break into FBI systems. The first PeopleSoft vulnerability is already being actively exploited. A possible second one has no patch, no CVE, and no vendor comment.

ThreatVectr NewsdeskAI-assistedPublished · Editor: Lee Brown· 4 min read
Illustration: A wide server room bathed in deep blue and orange light
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • ShinyHunters claims to have used a brand-new, unconfirmed PeopleSoft flaw to break into an FBI system and steal employee records, though no independent forensic confirmation exists.
  • CVE-2026-35273, the first PeopleSoft hole exploited by the group, carries a CVSS score of 9.8 out of 10 and allows full, unauthenticated remote access to affected systems.
  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA, the federal body that tracks actively attacked software flaws) added CVE-2026-35273 to its Known Exploited Vulnerabilities catalogue on 12 June 2026, giving federal agencies until 15 June 2026 to patch.
  • Law enforcement arrested a suspected ShinyHunters member, who is cooperating with investigators, but analysts say that does not reduce the technical threat.
  • One analyst described the situation as a potential "pattern of recurring critical exposure" inside a single product, not an isolated bug.

Oracle PeopleSoft is software that tens of thousands of universities, hospitals, government agencies and large companies use to manage HR records, payroll and finance. Getting full, unauthenticated access to it is about as bad as it gets.

That is exactly what CVE-2026-35273 allows. Published on 11 June 2026 and scored 9.8 by the Common Vulnerability Scoring System (CVSS, a 0-to-10 scale that measures how dangerous a flaw is), the bug sits inside the Updates Environment Management component of Oracle PeopleSoft Enterprise PeopleTools. An attacker needs no username, no password. They send a request over the internet and can take complete control of the system.

Oracle patched the flaw. CISA listed it as actively exploited two days later and gave federal agencies until 15 June to apply the fix. We first covered the active exploitation on 26 September in "ShinyHunters Hit Oracle PeopleSoft Bug That Hands Over the Whole System".

Many organisations did not patch. They installed web application firewall (WAF) rules instead, which are filters that try to block specific types of web requests. It did not work. According to Frank Dickson, principal analyst at Dickson Research, attackers bypassed those filters by substituting a single character: typing %50 in a URL instead of the letter P. The WAF saw a different string; the server processed it identically.

So what is the second flaw ShinyHunters is claiming?

ShinyHunters says it is a separate, previously unknown pre-authentication remote code execution flaw, meaning an attacker can run any software they like on a target server without logging in first. The group claims it used this to break into an FBI system and take records on all FBI employees. A suspected member has since been arrested and is cooperating with investigators. The FBI confirmed the breach but gave no technical details.

IDC Research Director Philip Harris urged caution: no CVE number has been assigned to this alleged second flaw, it has not appeared on CISA's catalogue, and Oracle has not acknowledged it. The only source for the claim is ShinyHunters itself.

That distinction matters. A real flaw means every PeopleSoft customer faces an active, unpatchable attack with zero vendor guidance. A fabricated one is still a distraction engineered by a group that has already demonstrated it can walk past enterprise defences. Neither outcome is comfortable.

Detail Value
CVE ID CVE-2026-35273
CVSS Score 9.8 (Critical)
CVE published 11 June 2026
CISA KEV added 12 June 2026
Federal patch deadline 15 June 2026

What should PeopleSoft customers do right now?

Apply Oracle's patch for CVE-2026-35273 immediately if you have not already. A firewall rule is not a substitute.

Dickson's advice goes further: pull the Environment Management Hub and the Integration Broker off the public internet entirely. Search system logs for encoded variants of the PSEMHUB path, not just the plain text string. If you find an unexpected file planted on the server (called a web shell, a backdoor that lets attackers run commands remotely), treat the whole server as compromised and rotate every credential it could have accessed.

Jeff Valdes, a director at consulting firm Acceligence, put Oracle's silence plainly: customers reasonably want to know whether the original patch guidance is still sufficient, whether additional steps exist, and whether certain configurations increase exposure. Those are answerable questions that have nothing to do with the FBI investigation.

My read: the WAF-bypass story alone should have pushed every PeopleSoft shop into emergency mode weeks ago. The unverified second-flaw claim is unconfirmed and probably designed partly to spread panic, but the underlying track record is what's damning. A group that found one 9.8-severity hole in this product, then trivially routed around enterprise defences while organisations patched too slowly, does not get the benefit of the doubt on a second claim.

© 2026 Threat Vectr