Critical Oracle PeopleSoft CVE-2024-XXXX RCE Zero-Day Exploited by ShinyHunters
Key Takeaways A critical zero-day vulnerability in Oracle PeopleSoft, CVE-2026-35273, was actively exploited by the ShinyHunters group (also known as UNC6240). The unauthenticated remote code...
Key Takeaways
- A critical zero-day vulnerability in Oracle PeopleSoft, CVE-2026-35273, was actively exploited by the ShinyHunters group (also known as UNC6240).
- The unauthenticated remote code execution (RCE) flaw, rated 9.8 CVSS, targeted the Environment Management Hub (PSEMHUB) component in PeopleTools versions 8.61 and 8.62.
- The campaign, active from May 27 to June 9, 2026, primarily impacted the higher education sector, with at least one university confirming data theft.
- Oracle released an emergency advisory on June 10, 2026, and organizations are urged to apply the patch immediately.
A sophisticated compromise and extortion campaign, attributed to the notorious threat actor UNC6240, known publicly as ShinyHunters, has targeted Oracle PeopleSoft infrastructure. Mandiant and the Google Threat Intelligence Group (GTIG) issued a joint critical warning detailing the operation, which leveraged a zero-day vulnerability for unauthenticated remote code execution.
Table Of Content
The attackers exploited CVE-2026-35273, a severe vulnerability with a CVSS score of 9.8, before Oracle could release its official advisory on June 10, 2026. This allowed ShinyHunters to gain unauthorized access and initiate data exfiltration.
Between May 27 and June 9, 2026, the campaign actively targeted the Environment Management Hub (PSEMHUB) component within Oracle PeopleSoft PeopleTools versions 8.61 and 8.62. The attackers systematically compromised vulnerable systems during this period.
GTIG identified over 100 global organizations with IP addresses correlating to potentially vulnerable endpoints. A significant majority, 68%, of these potential victims were concentrated within the higher education sector, including numerous universities and colleges worldwide.
The University of Nottingham publicly confirmed unauthorized activity on its systems, reporting the theft of approximately 40 gigabytes of sensitive data. This stolen information reportedly included student records, financial aid data, health records, and immigration details.
Oracle PeopleSoft 0-Day RCE Vulnerability
As part of their investigation, GTIG meticulously triaged five sequential attacker-controlled staging IP addresses, ranging from 142.11.200.186 to 142.11.200.190. Each of these IP addresses hosted a Python SimpleHTTP server on port 8888, revealing critical operational details.
These exposed directories contained a trove of attacker command histories, staging materials, and pre-configured MeshCentral remote management agents, providing insight into the group’s tactics.
The Windows agent binaries were cleverly disguised as legitimate Microsoft Azure services, specifically named meshagent32-azure-ops.exe, meshagent64-azure-ops.exe, and meshagent64-v2.exe. These agents were hardcoded to establish command-and-control (C2) communications with wss://azurenetfiles.net:443/agent.ashx, a domain carefully crafted to mimic legitimate Microsoft Azure NetApp Files endpoints and evade detection.
The attackers established their staging environment on May 27, 2026, at 22:14 UTC, by installing MeshCentral v1.1.59. Shortly after, at 22:25 UTC, they installed the acme-client npm package to automate the provisioning of Let’s Encrypt SSL certificates for their masquerading domain, enhancing the legitimacy of their infrastructure.
Utilizing the meshctrl.js command-line interface, the threat actors executed targeted reconnaissance commands on compromised hosts. They mapped Oracle PeopleSoft configurations by inspecting psappsrv.cfg, audited active NFS mounts, and read WebLogic config.xml files to comprehensively map internal application servers within the victims’ networks.
Lateral movement within the compromised environments was automated through a custom propagation script, named [victim_abbreviation]_fanout.sh, which was deployed to the /tmp directory. This script performed SSH credential spraying against internal hosts identified from /etc/hosts files.
Upon successful authentication, the script deployed a defacement and extortion marker file, named README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT, into the WebLogic and Process Scheduler directories, clearly signaling the breach to the victims.
Exfiltrated data was efficiently compressed using zstd before the attackers established an outbound SSH connection to 176.120.22.24. This IP address hosted the public mirror of the ShinyHunters Data Leak Site (DLS), where the stolen data archives were subsequently published on June 9, 2026.
What You Should Do
- Immediately apply Oracle’s emergency advisory for CVE-2026-35273 to all affected PeopleSoft installations.
- Ensure all Oracle PeopleSoft instances are running actively supported versions and have all Critical Patch Updates (CPUs) applied without delay.
- Review network logs for connections to the Indicator of Compromise (IOC) IP addresses and domains listed above.
- Scan systems for the presence of the identified MeshCentral agent binaries and the extortion marker file.
- Implement robust network segmentation to limit lateral movement in case of a breach.
- Conduct a thorough audit of all PeopleSoft configurations, user accounts, and access privileges.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.