logo

Critical RCE Vulnerability in Oracle PeopleSoft Exploited by SHADOW-AETHER-015

ID: 14c44ced-1374-5d7e-8bbf-6559ff3647a9

STIX ID: report--14c44ced-1374-5d7e-8bbf-6559ff3647a9

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-06-18

Date Updated: 2026-06-22

...
...

Oracle disclosed CVE-2026-35273, a pre-authentication RCE in PeopleSoft PeopleTools (versions 8.61 and 8.62) reported by TrendAI and publicly alerted on June 10, 2026. Mandiant confirmed active exploitation in a campaign labeled SHADOW-AETHER-015 that impacted more than 100 organizations—mainly in higher education—between May 27 and June 9, 2026; the exploit is particularly stealthy because it executes code on server restart without generating outbound traffic, and TrendAI has provided detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.