Vulnerabilities · 82 days ago

Internet-Facing PeopleSoft Console Becomes Extortion Foothold

An exposed PeopleSoft management console is not a small app bug. Once attackers can run commands there without logging in, they get a trusted admin channel into the environment, which is enough for reconnaissance, lateral movement, and extortion.

Google Threat Intelligence Group and Mandiant say ShinyHunters used a zero-day, CVE-2026-35273, against Oracle PeopleSoft Environment Management before Oracle had patches out. FortiGuard says the campaign hit mostly higher-education victims, with about 68% of identified targets in education, and the post-compromise activity included remote admin tooling, data theft, and extortion.

The blast radius is the managed environment, not the single server. If an admin layer is internet-facing, patching the web app alone does not remove the trust an attacker can abuse once they are inside.

CVE-2026-35273

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Known ransomware campaign use. EPSS 95% (100th percentile).

CISA federal remediation date Jun 15 · date passed

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-06-25

Editions

Related stories