ShinyHunters claimed it used a new Oracle PeopleSoft zero-day, CVE-2026-35273, to break into an FBI system and steal employee data, while analysts said the exposure goes beyond a simple patch issue. Security voices singled out PeopleSoft’s Environment Management Hub and Integration Broker as components that should not be left reachable from the public internet.
The problem is the management path, not normal user login. If attackers can reach those admin modules, they can use the admin plane as a back door into the PeopleSoft environment, and a server-side foothold can expose credentials and other secrets the system can read.
For PeopleSoft shops that expose those components, the lasting risk is that a patched core can still sit behind an internet-facing management layer. The reporting also leaves open how many deployments have that path open, which is the exposure that now matters most.