CVE-2026-35273 & CVE-2026-35278: The Oracle PeopleSoft Zero-Day Chain Behind 100+ Breaches
How threat actors chained two unauthenticated Oracle PeopleSoft zero-days to breach over 100 enterprise environments.
CVE-2026-35273 / 35278
Severity: CVSS 9.8
Status: ⚠️ Behind 100+ Enterprise Breaches
Target Component: Oracle PeopleSoft Enterprise HCM
What's Affected
Oracle PeopleSoft Enterprise PeopleTools, specifically the Updates Environment Management / PSEMHUB component. PeopleSoft PeopleTools underpins PeopleSoft's HCM, Financials, and Campus Solutions modules, which is why the affected population skews heavily toward universities, hospitals, and government agencies that run PeopleSoft for HR, payroll, and student systems.
The Vulnerabilities
CVE-2026-35278, CVSS 9.8: a pre-authentication remote code execution flaw in PeopleTools that gives an unauthenticated attacker initial code execution against an exposed PeopleSoft environment.
CVE-2026-35273: a related pre-authentication RCE in the Updates Environment Management component, used by attackers to escalate and pivot after initial access.
Attack Chain Breakdown
The financially motivated extortion group tracked as UNC6240, publicly known as ShinyHunters, ran a live intrusion campaign from May 27 to June 9, roughly two weeks of exploitation before any advisory existed. Attackers gained initial access by exploiting CVE-2026-35278 against internet-facing PeopleSoft PeopleTools instances, then used CVE-2026-35273 to escalate privileges and move deeper into the environment. Oracle's telemetry and third-party incident responders traced the campaign to approximately 300 compromised PeopleSoft installations spanning more than 100 organizations, with higher education institutions disproportionately represented given how widely PeopleSoft Campus Solutions is deployed.
The Bigger Patch: Oracle's Record July CPU
The PeopleSoft fix landed inside Oracle's largest Critical Patch Update to date: 1,434 CVEs across 334 products and 32 product families, including ten CVSS 10.0 vulnerabilities in Fusion Middleware alone (219 of the 355 Fusion Middleware patches address flaws exploitable without authentication). E-Business Suite received the most patches of any product line (410), a reminder that this CPU is not a one-off PeopleSoft patch cycle but a broad, unusually heavy release across Oracle's enterprise stack.
Indicators to Check For
Unexpected requests to PSEMHUB or Updates Environment Management endpoints from external IPs during the May 27 to June 9 window; new or modified administrator accounts within PeopleSoft; unfamiliar scheduled processes or App Engine programs; and outbound connections from PeopleSoft application servers to unfamiliar destinations, which would suggest data staging or exfiltration.
Remediation
Apply Oracle's July 2026 Critical Patch Update to all PeopleSoft PeopleTools instances immediately, and don't treat this as a routine quarterly patch given the confirmed pre-disclosure exploitation. Audit PeopleSoft environments for compromise indicators covering the May 27 to June 9 exploitation window even after patching, since patching closes the hole but doesn't remove an attacker who already got in. Given the scale of the CPU, prioritize the ten CVSS 10.0 Fusion Middleware flaws and any other internet-facing Oracle components next.
Related
This post is part of this week's Security Roundup: SharePoint's Next Zero-Day, Oracle's Record CPU, and the EY Breach (Week of July 20, 2026), at colibrisec.org/security-roundup-sharepoints-next-zero-day-cpu-and-the-ey-breach-week-of-july-20-2026/.