logo

Critical RCE Vulnerability in Oracle PeopleSoft Exploited by SHADOW-AETHER-015

ID: 6f9dfef5-0d45-518b-a154-d826dd335b6d

STIX ID: report--6f9dfef5-0d45-518b-a154-d826dd335b6d

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-06-18

Date Updated: 2026-06-19

...
...

**Executive summary:** A critical pre-authentication RCE (CVE-2026-35273) in Oracle PeopleSoft PeopleTools (8.61/8.62) is being actively exploited in the wild by a campaign named SHADOW-AETHER-015, impacting over 100 organizations—primarily higher education; TrendAI reported the issue via ZDI, Oracle issued an alert on 2026-06-10, and Mandiant confirmed active exploitation. The exploit is notable for low observability, as code executes on server restart without generating outbound traffic, and TrendAI has published detection guidance for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.