Executive Summary
Between May 27 and June 9, 2026, the cyber extortion group ShinyHunters exploited a zero-day vulnerability (CVE-2026-35273) in Oracle's PeopleSoft software, specifically targeting the Environment Management Hub (EMHub). This critical flaw allowed unauthenticated remote code execution, leading to the compromise of over 100 organizations, predominantly in the higher education sector. The attackers exfiltrated sensitive data from approximately 300 PeopleSoft instances, including personal and financial information of students and staff. Oracle released a security advisory and patch on June 10, 2026, urging immediate action to mitigate the risk. (darkreading.com)
This incident underscores the increasing targeting of educational institutions by cybercriminals exploiting unpatched vulnerabilities in widely used enterprise software. The rapid exploitation of zero-day vulnerabilities highlights the necessity for organizations to implement proactive vulnerability management and incident response strategies to protect sensitive data and maintain operational integrity.
Why This Matters Now
The ShinyHunters' exploitation of a zero-day vulnerability in Oracle's PeopleSoft software highlights the urgent need for organizations, especially in the education sector, to promptly apply security patches and strengthen their cybersecurity defenses to prevent data breaches and operational disruptions.
Attack Path Analysis
ShinyHunters exploited a zero-day vulnerability in Oracle's PeopleSoft software to gain unauthorized access to over 100 organizations, primarily in the higher education sector. They escalated privileges within the compromised systems, enabling further control and access. Utilizing tools like MeshCentral, they moved laterally across networks to expand their foothold. The attackers established command and control channels to manage their operations remotely. They exfiltrated large volumes of sensitive data, including student records and financial information. Finally, they issued ransom demands, threatening to leak the stolen data if their demands were not met.
Kill Chain Progression
Initial Compromise
Description
ShinyHunters exploited CVE-2026-35273, a zero-day vulnerability in Oracle's PeopleSoft software, to gain unauthorized access to over 100 organizations.
Related CVEs
CVE-2026-35273
CVSS 9.8A critical vulnerability in Oracle PeopleSoft PeopleTools' Updates Environment Management component allows unauthenticated remote code execution via HTTP, potentially leading to full system compromise.
Affected Products:
Oracle PeopleSoft Enterprise PeopleTools – 8.61, 8.62
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Command and Scripting Interpreter: PowerShell
Valid Accounts
Remote Services: Remote Desktop Protocol
Exfiltration Over C2 Channel
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Asset Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Higher Education/Acadamia
Oracle PeopleSoft zero-day exploitation by ShinyHunters specifically targeted universities, affecting 68% of victims with student data exfiltration and ransomware demands.
Government Administration
PeopleSoft ERP systems used for payroll and HR in government entities face critical RCE vulnerability enabling unauthorized access to sensitive administrative data.
Information Technology/IT
Oracle's critical CVE-2026-35273 vulnerability in PeopleSoft environments requires immediate patching and network segmentation to prevent lateral movement and data exfiltration attacks.
Financial Services
Enterprise resource planning systems handling payroll and financial data vulnerable to unauthenticated remote code execution requiring enhanced egress security and encryption controls.
Sources
- ShinyHunters Uses Oracle Zero-Day to Rampage Higher Edhttps://www.darkreading.com/vulnerabilities-threats/shinyhunters-oracle-zero-day-higher-edVerified
- Oracle Security Alert Advisory - CVE-2026-35273https://www.oracle.com/security-alerts/alert-cve-2026-35273.htmlVerified
- NVD - CVE-2026-35273https://nvd.nist.gov/vuln/detail/CVE-2026-35273Verified
- CVE-2026-35273 in Oracle PeopleSoft PeopleTools EMHub Under Active Exploitationhttps://socradar.io/blog/cve-2026-35273-oracle-peoplesoft-peopletools/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to move laterally, escalate privileges, and exfiltrate data by enforcing strict segmentation and access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix Zero Trust CNSF may not have prevented the initial exploitation of the zero-day vulnerability, it could have limited the attacker's ability to escalate privileges and move laterally within the network.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation could have limited the attacker's ability to escalate privileges by enforcing strict access controls and minimizing the attack surface.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security could have limited the attacker's ability to move laterally by enforcing strict segmentation and monitoring of internal traffic.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control could have limited the attacker's ability to establish and maintain command and control channels by providing comprehensive monitoring and control over network traffic.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement could have limited the attacker's ability to exfiltrate data by enforcing strict egress policies and monitoring outbound traffic.
While Aviatrix Zero Trust CNSF could have limited the attacker's ability to escalate privileges, move laterally, and exfiltrate data, the initial compromise may still have occurred, potentially leading to some data exposure.
Impact at a Glance
Affected Business Functions
- Student Records Management
- Human Resources
- Payroll Processing
- Supply Chain Management
Estimated downtime: 14 days
Estimated loss: $5,000,000
Personal identifiable information (PII) of students and staff, financial records, and sensitive institutional data.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement and limit attackers' ability to traverse networks.
- • Deploy East-West Traffic Security controls to monitor and control internal traffic, detecting unauthorized movements within the network.
- • Utilize Egress Security & Policy Enforcement to prevent unauthorized data exfiltration by controlling outbound traffic.
- • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to suspicious activities promptly.
- • Apply patches and updates promptly to mitigate vulnerabilities like CVE-2026-35273, reducing the risk of exploitation.



