Oracle PeopleSoft zero-day CVE-2026-35273 hit 100-plus organizations, mostly universities
ShinyHunters exploited the unpatched flaw for two weeks before Oracle's advisory. Have I Been Pwned counted about 455,000 leaked email records, most from higher education.
Oracle issued an out-of-band security advisory on June 10 for CVE-2026-35273, a critical remote-code-execution zero-day in PeopleSoft that attackers had already exploited to breach more than 100 organizations.
The case shows how a single unpatched enterprise flaw can cascade into a mass-data incident before a vendor responds. Rated CVSS 9.8, the vulnerability sits in the Environment Management Hub (PSEMHUB) component of PeopleSoft PeopleTools versions 8.61 and 8.62 and requires no authentication or user interaction — only HTTP network access to the target.
The threat group ShinyHunters, tracked as UNC6240, exploited the flaw between May 27 and June 9, 2026, before Oracle published any advisory, according to Google's Mandiant unit. Mandiant chief technology officer Charles Carmakal confirmed active exploitation on June 11, and Mandiant said it notified more than 100 global organizations with potentially vulnerable endpoints. About 68 percent of victims are in higher education, mostly in the United States; the University of Nottingham confirmed a breach and notified affected students and alumni.
The scale of exposed data is significant. Breach-tracking service Have I Been Pwned counted roughly 455,000 unique email addresses in the leaked dataset, alongside names, addresses, phone numbers, passport numbers, and academic records.
The situation was still unfolding as of June 11 reporting, with no patch confirmed available to all customers; Oracle recommended disabling PSEMHUB or blocking external access to the /PSEMHUB/* and /PSIGW/HttpListeningConnector paths as interim mitigations. The 455,000 figure comes from Have I Been Pwned rather than Oracle, and the victim count may rise as more organizations check their logs. Oracle credited the TrendAI Zero Day Initiative and TrendAI Research for the discovery.
With exploitation confirmed and a mitigation but no broadly available fix in hand, PeopleSoft administrators face pressure to restrict the vulnerable component immediately and hunt for signs of an existing compromise.
Founder and Chief Editor of Data Phoenix — a San Francisco Bay Area media and education platform focused on AI and Data.
More news

AWS releases six open-source Hugging Face deployment skills for SageMaker

Google Research releases MilleMiglia logistics benchmark generator

AWS launches AgentCore Runtime V2 with elastic memory and snapshot starts
