logo

Oracle PeopleSoft RCE Vulnerability Exploited in the Wild

ID: ef6b3d7f-27b7-5db5-87d1-a34de215a5ab

STIX ID: report--ef6b3d7f-27b7-5db5-87d1-a34de215a5ab

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-06-18

Date Updated: 2026-06-21

...
...

A critical pre-authentication remote code execution vulnerability (CVE-2026-35273) in Oracle PeopleSoft PeopleTools (versions 8.61 and 8.62) has been actively exploited via the Integration Broker PSIGW gateway. TrendAI reports link the exploitation to the SHADOW-AETHER-015 (ShinyHunters) campaign that targeted over 100 organizations—mainly higher-education institutions—between May 27 and June 9, 2026; the attack is notable for stealthy post-restart code execution without observable network activity and carries a CVSS score of 9.8.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.