Oracle PeopleSoft zero-day CVE-2026-35273 exploited by ShinyHunters, universities hit hardest
Any organization still running unpatched Oracle PeopleSoft $ORCL can be taken over with no login and no clicks, just HTTP access. Google's Mandiant ties a zero-day extortion campaign (CVE-2026-35273, rated 9.8/10) to ShinyHunters. 68% of victims were universities, most in the US.
Any organization still running an unpatched Oracle PeopleSoft $ORCL system is exposed to full server takeover that needs no login, no stolen password, and no user interaction, just network access over HTTP. Google's Mandiant has attributed an extortion campaign exploiting this flaw, tracked as CVE-2026-35273 and rated 9.8 out of 10, to the group it calls ShinyHunters (UNC6240). According to Mandiant, the attacks ran between May 27 and June 9, while Oracle did not publish its security advisory until June 10. That means the bug was a true zero-day the entire time it was being used, giving defenders no signature to detect and no patch to apply. The education sector absorbed the worst of it. Mandiant reports that 68 percent of identified victims were universities, most of them in the United States, where PeopleSoft is widely used to run student records, payroll, and HR. The attackers stole data first, then demanded payment to keep it private. For any institution that has not yet applied Oracle's fix, the window between silent exploitation and public disclosure is the part that matters most: by the time the advisory existed, sensitive records may already have left the building.