ShinyHunters Hit Oracle PeopleSoft Bug That Hands Over the Whole System

A critical flaw in Oracle's PeopleSoft business software is under active attack, with federal agencies given days to patch.

ThreatVectr Newsdesk· Editor: Lee Brown· 3 min read
Full-frame edge-to-edge photoreal news-editorial image of a dimly lit enterprise server rack with amber warning LEDs reflecting off glossy black cabinet doors,
Share

Key points

  • ShinyHunters-linked attackers are running mass exploitation of CVE-2026-35273, rated 9.8 out of 10 for severity, against Oracle PeopleSoft servers worldwide.
  • The bug lets an attacker take full control of a PeopleSoft server from the internet without a password, according to Oracle's security alert published 11 June 2026.
  • The US Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalogue and gave federal agencies a narrow window to fix it.
  • Google's researchers say the bug was first used as a zero-day, meaning attackers found it before Oracle knew it existed.
  • Attackers are bypassing web application firewalls and installing web shells to keep a permanent back door open.

Oracle PeopleSoft is the back-office software many large employers and government departments use to run payroll, student records and human resources. Hijack that server and you're inside the plumbing of the organisation.

That's what's happening now.

Who is ShinyHunters?

ShinyHunters is a data-theft and extortion crew active since 2020, known for stealing customer databases and selling them on criminal forums. It doesn't run file-locking ransomware in the classic sense. The crew steals, demands payment to keep data offline, and has moved comfortably between forum sales and direct shakedowns. We covered a recent example of their methods on 17 September in "ShinyHunters Claims Theft of 200,000+ Florida Driver Records From State DMV System", where the group claimed to have abused a password-reset flaw in a Florida law-enforcement database.

Google's researchers link the current PeopleSoft wave to ShinyHunters-associated activity, reporting that attackers are getting past web application firewalls (the filters companies put in front of web servers to block obvious attacks) and dropping web shells that give them a permanent back door.

What the bug actually does

The flaw sits in a component called Updates Environment Management inside PeopleTools. A piece of software that should check who is calling doesn't check at all. Send a normal-looking web request and you're running your own code on the server.

No login. No clever chain of other bugs required. No user action on the victim's end.

That's why the score is 9.8. Oracle rates it as remotely exploitable without authentication, warning it can lead to remote code execution, which means the attacker runs whatever they want on your machine.

Fact Detail
CVE ID CVE-2026-35273
CVSS score 9.8 (critical)
Oracle alert published 11 June 2026
Exploitation type Zero-day, unauthenticated

Should ordinary people worry?

Probably not directly, but the fallout can reach you. PeopleSoft holds staff and student records at large organisations, so a break-in can expose names, addresses and salary details. If your employer or a government body you deal with reports an HR system breach in the coming weeks, this is likely why.

Watch for letters offering credit monitoring. Be sceptical of emails claiming to come from your HR or payroll team, because stolen internal data makes those scams far more convincing.

What to watch next

CISA's tight patch deadline signals the US government believes this is being hit hard right now. Expect leak-site listings naming PeopleSoft victims to appear on ShinyHunters-adjacent Telegram channels within weeks. This crew's pattern is quiet theft first, public extortion later, and nothing in the current campaign suggests a change in approach.

© 2026 Threat Vectr