CVE-2026-35273 & CVE-2026-35278: The Oracle PeopleSoft Zero-Day Chain Behind 100+ Breaches

How threat actors chained two unauthenticated Oracle PeopleSoft zero-days to breach over 100 enterprise environments.

CVE-2026-35273 & CVE-2026-35278: The Oracle PeopleSoft Zero-Day Chain Behind 100+ Breaches
Photo by Kevin Ache / Unsplash
📌
Security Roundup Series: Week of July 20, 2026 • 4 min read deep dive
🚨
Threat Intelligence & Technical Specs: CVE ID: CVE-2026-35273 / 35278 Severity: CVSS 9.8 Status: ⚠️ Behind 100+ Enterprise Breaches Target Component: Oracle PeopleSoft Enterprise HCM

What's Affected

Oracle PeopleSoft Enterprise PeopleTools, specifically the Updates Environment Management / PSEMHUB component. PeopleSoft PeopleTools underpins PeopleSoft's HCM, Financials, and Campus Solutions modules, which is why the affected population skews heavily toward universities, hospitals, and government agencies that run PeopleSoft for HR, payroll, and student systems.

The Vulnerabilities

CVE-2026-35278, CVSS 9.8: a pre-authentication remote code execution flaw in PeopleTools that gives an unauthenticated attacker initial code execution against an exposed PeopleSoft environment.

CVE-2026-35273: a related pre-authentication RCE in the Updates Environment Management component, used by attackers to escalate and pivot after initial access.

Attack Chain Breakdown

The financially motivated extortion group tracked as UNC6240, publicly known as ShinyHunters, ran a live intrusion campaign from May 27 to June 9, roughly two weeks of exploitation before any advisory existed. Attackers gained initial access by exploiting CVE-2026-35278 against internet-facing PeopleSoft PeopleTools instances, then used CVE-2026-35273 to escalate privileges and move deeper into the environment. Oracle's telemetry and third-party incident responders traced the campaign to approximately 300 compromised PeopleSoft installations spanning more than 100 organizations, with higher education institutions disproportionately represented given how widely PeopleSoft Campus Solutions is deployed.

The Bigger Patch: Oracle's Record July CPU

The PeopleSoft fix landed inside Oracle's largest Critical Patch Update to date: 1,434 CVEs across 334 products and 32 product families, including ten CVSS 10.0 vulnerabilities in Fusion Middleware alone (219 of the 355 Fusion Middleware patches address flaws exploitable without authentication). E-Business Suite received the most patches of any product line (410), a reminder that this CPU is not a one-off PeopleSoft patch cycle but a broad, unusually heavy release across Oracle's enterprise stack.

Indicators to Check For

Unexpected requests to PSEMHUB or Updates Environment Management endpoints from external IPs during the May 27 to June 9 window; new or modified administrator accounts within PeopleSoft; unfamiliar scheduled processes or App Engine programs; and outbound connections from PeopleSoft application servers to unfamiliar destinations, which would suggest data staging or exfiltration.

Remediation

Apply Oracle's July 2026 Critical Patch Update to all PeopleSoft PeopleTools instances immediately, and don't treat this as a routine quarterly patch given the confirmed pre-disclosure exploitation. Audit PeopleSoft environments for compromise indicators covering the May 27 to June 9 exploitation window even after patching, since patching closes the hole but doesn't remove an attacker who already got in. Given the scale of the CPU, prioritize the ten CVSS 10.0 Fusion Middleware flaws and any other internet-facing Oracle components next.

This post is part of this week's Security Roundup: SharePoint's Next Zero-Day, Oracle's Record CPU, and the EY Breach (Week of July 20, 2026), at colibrisec.org/security-roundup-sharepoints-next-zero-day-cpu-and-the-ey-breach-week-of-july-20-2026/.


Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther