Oracle PeopleSoft Zero-Day Breaches 100+ Companies

ShinyHunters exploited critical Oracle PeopleSoft vulnerability affecting over 100 organizations. CVSS 9.8 flaw remains unpatched as Oracle investigates.

Oracle customers are facing a significant security crisis as threat actors have successfully exploited a critical zero-day vulnerability in PeopleSoft software, compromising more than 100 organizations worldwide. The vulnerability, tracked as CVE-2026-35273, represents one of the most severe threats to enterprise systems in recent months.

What Happened

Oracle disclosed the vulnerability on Thursday following active exploitation by the ShinyHunters hacking group. The flaw carries a critical CVSS severity score of 9.8, indicating near-maximum risk to affected systems. Most alarmingly, the vulnerability can be exploited remotely without requiring any form of authentication, making it accessible to attackers across the internet. The breach notification came just one day after initial discovery, highlighting the rapid pace of exploitation in the wild. To date, Oracle has not released a security patch to remediate the issue, leaving organizations in a precarious position.

Key Points

PeopleSoft is widely deployed across enterprise environments, with thousands of organizations relying on the platform for human resources, financial management, and supply chain operations. The widespread adoption means this vulnerability potentially affects critical business infrastructure across multiple industries and sectors. The fact that over 100 companies have already been breached before patch availability demonstrates the sophisticated nature of the attack campaign. Security researchers indicate that ShinyHunters, a known threat group, leveraged the vulnerability to gain unauthorized access to sensitive corporate data. The remote, unauthenticated nature of the exploit significantly reduces the barrier to entry for attackers, potentially enabling script kiddies and less sophisticated threat actors to launch attacks.

What This Means

Organizations running affected PeopleSoft versions face an immediate security crisis with limited remediation options. Until Oracle releases a patch, companies must implement aggressive compensating controls, including network segmentation, enhanced monitoring, and access restrictions. Security teams should prioritize identifying whether their infrastructure is running vulnerable PeopleSoft versions and assess breach indicators. The incident underscores the importance of prompt vendor response to critical vulnerabilities and highlights the risks of delayed patching cycles in enterprise environments. For CISOs and security leaders, this breach serves as a critical reminder to implement zero-trust security principles and maintain robust incident response capabilities. Organizations should also consider isolating affected PeopleSoft instances from internet-facing networks and implementing additional authentication layers where possible. As Oracle develops and releases patches, companies must prioritize rapid deployment to prevent further compromise.

Leave a Reply

Your email address will not be published. Required fields are marked *