# ShinyHunters exploits PeopleSoft zero-day CVE-2026-35273

Published: 2026-06-11 · Severity: critical · Sectors: technology
Canonical: https://vorant.io/reports/2c3da196-e27e-421c-8fee-2c85120d345d/shinyhunters-exploits-peoplesoft-zero-day-cve-2026-35273

> Oracle mitigates critical PeopleSoft zero-day (CVE-2026-35273, CVSS 9.8) exploited by ShinyHunters gang to breach 300+ instances and steal corporate data.

Oracle has released emergency mitigations for CVE-2026-35273, a critical zero-day vulnerability in PeopleSoft PeopleTools versions 8.61 and 8.62 that enables unauthenticated remote code execution with a CVSS score of 9.8. The flaw has been actively exploited by the ShinyHunters extortion gang in a widespread data theft campaign targeting enterprise PeopleSoft deployments.

ShinyHunters confirmed to BleepingComputer that they leveraged a "gadget chain" combining old and zero-day vulnerabilities to breach approximately 300 PeopleSoft instances across more than 100 organizations. The threat actor's typical modus operandi involves exfiltrating large volumes of corporate data from cloud SaaS platforms and enterprise systems, then demanding ransom payments to prevent public disclosure. Mandiant CTO Charles Carmakal independently confirmed active exploitation of this vulnerability.

Oracle has issued mitigations ahead of a full patch release. Organizations running affected PeopleSoft versions should immediately apply available mitigations and review access logs for connections from known attacker infrastructure, including IP addresses in the 142.11.200.0/24 range and additional indicators shared by security researchers. ShinyHunters has been linked to multiple high-profile breaches of cloud platforms including Snowflake and Salesforce over the past year.

## Mentioned in this report

- Vulnerabilities: CVE-2026-35273 (KEV)
- Threat actors: ShinyHunters

1 more detection artefacts for this report (IOC-atomic rules, Splunk/KQL/Elastic conversions, YARA, Suricata) are available to subscribers.

Source reporting: https://www.bleepingcomputer.com/news/security/oracle-mitigates-peoplesoft-zero-day-exploited-in-data-theft-attacks/

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/2c3da196-e27e-421c-8fee-2c85120d345d/shinyhunters-exploits-peoplesoft-zero-day-cve-2026-35273.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
