Critical CVSS 9.8 Vulnerability in Oracle PeopleSoft: ShinyHunters Exploits Zero-Day for 14 Days
Between May 27 and June 9, 2026, the group ShinyHunters exploited a critical zero-day vulnerability in Oracle PeopleSoft, compromising over 100 organizations worldwide before Oracle even released a security bulletin. At the time of publication on June 10, no patch was available.
CVE-2026-35273 affects the Updates Environment Management Hub (PSEMHUB) component of Oracle PeopleSoft Enterprise PeopleTools in versions 8.61 and 8.62. The CVSS score is 9.8: the vulnerability can be exploited remotely without authentication and, if successful, allows remote code execution on the affected system. Oracle recommended that customers apply immediate mitigations without releasing a fix.
The Campaign: Higher Education in the Crosshairs
Mandiant (Google Threat Intelligence Group) confirmed active exploitation and notified over 100 global organizations whose IP addresses matched potentially vulnerable endpoints. According to Mandiant's reconstruction, ShinyHunters targeted around 300 Oracle PeopleSoft servers within the victim organizations. The 68% of the victims operate in the higher education sector, with most located in the United States.
After the initial access via PSEMHUB, the attackers installed custom MeshCentral agents disguised as Microsoft Azure services, establishing communication with a command and control server at azurenetfiles.net. For lateral movement, they used a script named [victim_abbreviation]_fanout.sh, which automates credential spraying via SSH with a hardcoded list of common credentials. They deposited a file named README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT in the WebLogic and Process Scheduler directories.
The University of Nottingham is the first publicly confirmed victim. ShinyHunters released 40 GB of personal data and billing documentation on June 10, presumably after the university refused to pay the ransom. Have I Been Pwned monitored around 454,600 unique email addresses in the leak. The data includes names, addresses, phone numbers, passport numbers, ethnicity, disabilities, and information on academic enrollments and university fees.
On the mitigation front, Mandiant recommends disabling the Environment Management Hub service or blocking external access to the endpoints /PSEMHUB/ and /PSIGW/HttpListeningConnector. WAF rules with body inspection alone are insufficient as they can be bypassed.
ShinyHunters stated that the campaign has just begun and that most impacted organizations have not yet been made public. The group had already exploited vulnerabilities in Salesforce, Gainsight, and Instructure Canvas in the twelve months prior.