Oracle mitigates PeopleSoft zero-day exploited in data theft attacks
Oracle has mitigated a critical PeopleSoft zero-day, CVE-2026-35273, after attackers used it in data theft campaigns. A patch is coming soon.
Intelligence analysis by GPT-5.4 Mini

Oracle says a critical PeopleSoft PeopleTools flaw, CVE-2026-35273, can allow unauthenticated remote code execution. BleepingComputer and Mandiant tied it to ShinyHunters-style data theft attacks, with more than 100 organizations notified.
A locked door in a school office system had a hidden weakness, and burglars found it before the lock maker could fully fix it. Oracle has put up emergency barriers, but teams still need to check for footprints and broken windows.
Analysis
What Oracle confirmed
Oracle says CVE-2026-35273 affects PeopleSoft PeopleTools versions 8.61 and 8.62. The company describes it as remotely exploitable without authentication and capable of remote code execution, which is why the flaw carries a CVSS score of 9.8. Oracle has released emergency mitigations and says a full patch is coming soon.
How attackers used it
BleepingComputer reports that the bug was the zero-day used in data theft attacks linked to ShinyHunters. The article says the group claimed it used a "gadget chain" of old and zero-day flaws to break into PeopleSoft instances and steal data from 300 instances across more than 100 organizations. Mandiant later confirmed that threat actors were exploiting the Oracle PeopleSoft flaw as a zero-day and said most of the organizations it notified were based in the United States, with 68% in higher education.
What the defenders saw
According to Mandiant, the attackers did more than simple intrusion. They used customized MeshCentral remote management agents disguised as Microsoft Azure services, staged tools on their infrastructure, and moved through compromised networks by mapping PeopleSoft and WebLogic configurations. The researchers also said the attackers used scripts for lateral movement.
What security teams should do
Mandiant advised organizations to restrict access to sensitive PeopleSoft endpoints tied to the exploit chain, review logs for suspicious requests to /PSEMHUB/ and /PSIGW/HttpListeningConnector, and look for webshells, unauthorized files, and other signs of compromise. The article also notes that BleepingComputer reached out to Oracle for comment but had not received a response at publication time.
Key points
- Oracle says CVE-2026-35273 is a critical PeopleSoft PeopleTools zero-day that can enable unauthenticated remote code execution.
- BleepingComputer reports the flaw was actively used in ShinyHunters-linked data theft attacks.
- Mandiant said it notified more than 100 global organizations, most of them in the United States and many in higher education.
- Attackers reportedly used customized MeshCentral agents and mapped PeopleSoft and WebLogic setups inside compromised networks.
- Oracle has issued emergency mitigations and says a patch is coming soon.
Oracle has already shipped emergency mitigations, which can reduce exposure before the full patch arrives. Mandiant also shared concrete hunting guidance, giving defenders a clearer path to spot suspicious activity and contain damage.
If organizations delay mitigation, attackers may keep using the flaw to steal data or move deeper into internal systems. The article suggests the campaign already reached many organizations, so any unpatched PeopleSoft instance may remain a live target until the final fix is deployed.



