Security Roundup: Oracle PeopleSoft Zero-Day, June Patch Tuesday, Chrome V8 Exploit, TanStack Supply Chain — Week of June 12, 2026
Weekly briefing: Oracle PeopleSoft zero-day exploited by ShinyHunters, Chrome V8 in-browser RCE, and TanStack Mini Shai-Hulud worm.
A week dominated by the largest Patch Tuesday in Microsoft's history, a critical Oracle PeopleSoft zero-day actively exploited by the ShinyHunters extortion crew against universities, a Chrome V8 zero-day added to CISA's KEV catalog, a sophisticated npm supply chain worm targeting developer tooling, and a critical FortiSandbox command injection flaw. Here is everything you need to know and act on.
1. CVE-2026-35273 — Oracle PeopleSoft Zero-Day RCE Exploited by ShinyHunters: 100+ Orgs Breached (CVSS 9.8)
Google's Mandiant tracked the campaign—attributing it to UNC6240 (ShinyHunters)—between May 27 and June 9, 2026. Oracle did not publish its out-of-band advisory until June 10, meaning the bug was a zero-day for the entire campaign window. CVE-2026-35273 is an unauthenticated remote code execution vulnerability in Oracle PeopleSoft Enterprise PeopleTools: no credentials, no interaction, just a single crafted HTTP request over the PeopleSoft web tier.
CVSS: 9.8 Critical | CVE: CVE-2026-35273 | Vendor: Oracle (out-of-band advisory June 10, 2026)
Scale: 300+ vulnerable internet-facing instances identified. 100+ organizations confirmed compromised, 68% in higher education. Have I Been Pwned counted ~455,000 unique email addresses in leaked data including names, addresses, phone numbers, passport numbers, and sensitive personal attributes.
Attack chain: Attacker sends crafted HTTP POST to PeopleSoft's web tier (Jolt protocol or HTTP gateway) → unauthenticated deserialization/injection triggers RCE as the PeopleSoft application user → attacker drops a fanout script ([victim]_fanout.sh) that spreads over SSH using credentials from /etc/hosts and leaves a ransom marker file README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT in PeopleSoft directories → data exfiltration and extortion demand.
IOCs: Marker file README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT in PeopleSoft content directories; fanout script pattern [victim]_fanout.sh; outbound SSH spray from compromised PeopleSoft hosts.
Remediation: Apply Oracle's June 2026 out-of-band patch immediately. If patching is delayed, restrict PeopleSoft web tier access (ports 80/443/8000) to known IP ranges via WAF or firewall. Audit PeopleSoft directories for the marker file. Rotate all credentials on affected systems. Review SSH authorized_keys across adjacent hosts.
2. Microsoft June 2026 Patch Tuesday — Record 200+ CVEs, Six Zero-Days Including YellowKey WinRE Backdoor
Microsoft's June 2026 Patch Tuesday is the largest in the program's history, addressing 200+ vulnerabilities with 33 rated Critical (28 RCE, 4 EoP, 1 info disclosure). Six zero-days were patched, including three that had been publicly disclosed and two with physical-access exploitation chains.
Key zero-days:
- CVE-2026-45585 (YellowKey) — BitLocker bypass via Windows Recovery Environment (WinRE). Publicly known. Attacker with physical access exploits FsTx driver + WinRE interaction to bypass BitLocker Device Encryption without credentials. Affects Windows 11 and Server 2022/2025. CVSS 6.8.
- CVE-2026-45586 (CTFMON EoP) — Windows Collaborative Translation Framework elevation of privilege via improper link following. Grants SYSTEM. Publicly disclosed. CVSS 7.8.
- CVE-2026-49160 (HTTP.sys DoS) — HTTP/2 Bomb attack against IIS and other Windows HTTP.sys-backed servers. Publicly disclosed. CVSS 7.5.
- GreenPlasma / MiniPlasma — Two additional privilege escalation zero-days patched this cycle (details in companion deep-dive).
Affected: Windows 10/11, Windows Server 2016 through 2025; Office, Exchange, Azure, .NET runtime.
Remediation: Deploy June 2026 Patch Tuesday updates via WSUS/Intune/SCCM immediately. Prioritize domain controllers and internet-facing servers. For systems that cannot be patched immediately, enforce BitLocker PIN requirements to mitigate YellowKey physical access risk. Verify KB numbers: KB5060842 (Server 2022), KB5060840 (Server 2019), KB5060836 (Server 2025), KB5060533 (Windows 11 24H2).
3. CVE-2026-11645 — Chrome V8 Zero-Day OOB Read/Write Exploited in the Wild (CVSS 8.8)
Google shipped Chrome 149.0.7827.102/.103 on June 8, 2026 with an emergency patch for CVE-2026-11645, an out-of-bounds read and write in the V8 JavaScript engine. Google confirmed exploitation in the wild. CISA added it to the KEV catalog on June 9 with a required remediation deadline of June 23, 2026 for FCEB agencies.
CVSS: 8.8 High | CVE: CVE-2026-11645 | CISA KEV: June 9, 2026
Technical: The vulnerability is an out-of-bounds memory access in V8 that allows a remote attacker with a crafted HTML page to execute arbitrary code within the Chrome sandbox. This is the fifth actively exploited Chrome zero-day patched in 2026 (following CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281). A successful exploit at this stage still requires a sandbox escape for full system compromise, but in-browser exploitation is sufficient for credential theft, session hijacking, and cryptomining injection.
Remediation: Update Chrome to 149.0.7827.102 or later immediately. Enterprise admins: force update via policy or deploy via endpoint management. Verify: chrome://settings/help. Edge users: await corresponding Chromium-based update (typically within 24–48 hours of Chrome stable release).
4. TanStack npm Supply Chain Worm — "Mini Shai-Hulud" Backdoors 42 Packages, 12M Weekly Downloads
The threat actor group TeamPCP executed a sophisticated supply chain attack on May 11, 2026 (continuing impact through late May), compromising 42 @tanstack/* npm packages totalling 12 million weekly downloads. The attack was detected within 20–26 minutes by external researcher @ashishkurmi (StepSecurity), but by then malicious versions had propagated. The campaign expanded to 160+ packages across npm and PyPI under the "Mini Shai-Hulud" worm designation.
Attack mechanism: Attacker forked TanStack/router → submitted a PR triggering a pull_request_target workflow → poisoned the GitHub Actions pnpm cache with a malicious store → the legitimate TanStack release pipeline published 84 malicious package versions using TanStack's own trusted OIDC identity. No credential theft was required—the attacker hijacked the runner mid-workflow.
Malware payload: When a developer or CI runs npm install against any affected version, a ~2.3 MB obfuscated router_init.js executes via the prepare lifecycle hook. It exfiltrates: GitHub tokens, AWS keys, GCP service account credentials, SSH keys, CI/CD tokens, and Docker registry tokens to a C2.
IOCs: C2 infrastructure associated with TeamPCP (see deep-dive for full IOC list). Malicious pnpm cache entries. Presence of router_init.js as an optionalDependency in affected package versions.
Affected versions: All @tanstack/* packages published between 19:20–19:26 UTC on May 11, 2026. Check your package-lock.json against the confirmed clean version list in the deep-dive.
Remediation: Update all @tanstack/* packages to the latest verified clean versions (post-May 11 20:00 UTC). If any affected versions ran in your environment: rotate all secrets in CI/CD, cloud providers, and version control immediately. Enable Artifact Attestations and SLSA verification for your npm dependencies. Pin your GitHub Actions to commit SHAs, not tags.
5. FortiSandbox CVE-2026-25089 (CVSS 9.1) + CISA KEV Adds Arista EOS, Cisco SD-WAN, Chrome V8
Fortinet disclosed CVE-2026-25089, a critical OS command injection in the FortiSandbox Web UI's "start VNC" feature. Specially crafted JSON input to the endpoint triggers second-order command injection, allowing unauthenticated remote code execution on the underlying system. There are no reports of active exploitation at time of writing, but the CVSS 9.1 score and unauthenticated attack vector make this a high-priority patch.
CVSS: 9.1 Critical | CVE: CVE-2026-25089 | Advisory: FG-IR-26-141 (June 9, 2026)
Affected: FortiSandbox 5.0.0–5.0.5, 4.4.0–4.4.8, all 4.2.x; FortiSandbox Cloud 5.0.4–5.0.5; FortiSandbox PaaS 5.0.4–5.0.5.
Fixed in: FortiSandbox 5.0.6, 4.4.9; Cloud/PaaS 5.0.6.
On June 9, CISA also added three new entries to the KEV catalog, each requiring FCEB remediation by June 23:
- CVE-2026-7473 — Arista EOS Incomplete Comparison vulnerability (network OS). Network operators: verify EOS patch status immediately.
- CVE-2026-11645 — Google Chromium V8 OOB (covered above).
- CVE-2026-20245 — Cisco Catalyst SD-WAN Manager improper output encoding. Cisco has released patches; prioritize if SD-WAN Manager is internet-facing.
Also patched this cycle: Ivanti and SAP released patches for multiple critical vulnerabilities—see vendor advisories for CVSS scores and affected product versions.
Deep Dives
For full technical analysis, attack chain breakdowns, IOCs, and remediation commands, see the individual deep-dive posts:
- CVE-2026-35273: Oracle PeopleSoft Zero-Day — ShinyHunters UNC6240 Attack Chain & Remediation
- Microsoft June 2026 Patch Tuesday Deep Dive — YellowKey, GreenPlasma, CTFMON EoP & Record 200+ CVEs
- CVE-2026-11645: Chrome V8 Zero-Day — OOB Read/Write In-Browser RCE Analysis
- TanStack npm "Mini Shai-Hulud" Supply Chain Worm — TeamPCP Attack Chain, IOCs & Full Remediation
- CVE-2026-25089: FortiSandbox Unauthenticated RCE + CISA KEV June 9 Additions