Critical RCE Vulnerability in Oracle PeopleSoft Exploited by SHADOW-AETHER-015
ID: 6f9dfef5-0d45-518b-a154-d826dd335b6d
STIX ID: report--6f9dfef5-0d45-518b-a154-d826dd335b6d
Feed Name: ThreatCluster
**Executive summary:** A critical pre-authentication RCE (CVE-2026-35273) in Oracle PeopleSoft PeopleTools (8.61/8.62) is being actively exploited in the wild by a campaign named SHADOW-AETHER-015, impacting over 100 organizations—primarily higher education; TrendAI reported the issue via ZDI, Oracle issued an alert on 2026-06-10, and Mandiant confirmed active exploitation. The exploit is notable for low observability, as code executes on server restart without generating outbound traffic, and TrendAI has published detection guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
