ctipilot.ch

Oracle PeopleSoft PeopleTools PSEMHUB pre-auth RCE (CVSS 9.8), zero-day exploited by UNC6240/ShinyHunters

cve · CVE-2026-35273

Coverage timeline
5
first 2026-06-12 → last 2026-07-01
Peak priority
critical
2 critical · 2 high · 1 notable
Sources cited
16
11 hosts
Sections touched
3
updates, weekly-long-running, weekly-top-stories
Co-occurring entities
2
see Related entities below
ATT&CK techniques
3
pinned v19.1 · see below

ATT&CK techniques

3 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-06-12/shinyhunters-peoplesoft-campaign-oracle-confirms-cve-2026-35 · ATT&CK page ↗

Lateral Movement TA0008

T1021Remote Services×1

Adversaries may use Valid Accounts to log into a service that accepts remote connections, such as telnet, SSH, and VNC. The adversary may then perform actions as the logged-on user.

Evidence: 2026-06-12/shinyhunters-peoplesoft-campaign-oracle-confirms-cve-2026-35 · ATT&CK page ↗

T1021.004Remote Services: SSH×1

Adversaries may use Valid Accounts to log into remote machines using Secure Shell (SSH). The adversary may then perform actions as the logged-on user.

Evidence: 2026-06-12/shinyhunters-peoplesoft-campaign-oracle-confirms-cve-2026-35 · ATT&CK page ↗

Story timeline

  1. 2026-07-01Nissan is the largest named victim yet in the ShinyHunters Oracle PeopleSoft campaign
    updates
  2. 2026-06-29ShinyHunters / UNC6240 Oracle PeopleSoft campaign
    weekly-long-running
  3. 2026-06-29NAIC breached through an Oracle PeopleSoft zero-day; ShinyHunters dumps 3.1 TB and US rating-agency feeds stall
    weekly-top-stories
  4. 2026-06-13Oracle PeopleSoft CVE-2026-35273 attributed to ShinyHunters; confirmed zero-day, 100+ victims, education sector hit hardest
    updates
  5. 2026-06-12ShinyHunters PeopleSoft campaign — Oracle confirms CVE-2026-35273 and ships an out-of-band patch; Nottingham quantifies 455,000 records
    updates

Where this entity is cited

  • updates3
  • weekly-top-stories1
  • weekly-long-running1

Source distribution

  • securityweek.com3 (19%)
  • attack.mitre.org2 (12%)
  • bleepingcomputer.com2 (12%)
  • cloud.google.com2 (12%)
  • content.naic.org1 (6%)
  • insurancejournal.com1 (6%)
  • nottingham.ac.uk1 (6%)
  • oracle.com1 (6%)
  • other3 (19%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

External references

NVD · cve.org · CISA KEV

All cited sources (16)

Entries about Oracle PeopleSoft PeopleTools PSEMHUB pre-auth RCE (CVSS 9.8), zero-day exploited by UNC6240/ShinyHunters (5)

2026-07-01 · view entry permalink →

HIGHCVE-2026-35273exploitedupdate

Nissan is the largest named victim yet in the ShinyHunters Oracle PeopleSoft campaign

UPDATE · originally covered NAIC breached via Oracle PeopleSoft zero-day; ShinyHunters publishes 3.1 TB of US insurance-regulatory data and rating-agency feeds pause (2026-06-28)

Nissan disclosed that current and former employees' data was exposed via CVE-2026-35273, the Oracle PeopleSoft PeopleTools pre-auth flaw exploited as a zero-day between 2026-05-27 and 2026-06-09 as part of the wider ShinyHunters campaign (SecurityWeek, 2026-06-30). The exposure spans current and former employees in the US, Canada, Mexico and Brazil, potentially including Social Security numbers, banking/direct-deposit information and tax records.

This is a materially different victim profile from the previously-covered NAIC breach — employee HR/payroll PII rather than regulatory data — showing the campaign spreading across both regulatory-body and corporate-HR PeopleSoft deployments. As mitigation, Nissan restricted pay-slip viewing and direct-deposit changes to company-network/VPN-authenticated sessions and is offering credit/dark-web monitoring (BleepingComputer, 2026-06-29). ShinyHunters' self-reported scale of "over 300 PeopleSoft instances across ~100 organizations" is an unverified actor claim — attribute the claim, not confirmed fact. No new technical detail beyond victim-count expansion; the operative guidance from the 2026-06-28 NAIC item stands (patch CVE-2026-35273; remove internet-exposed PeopleSoft PeopleTools from public reachability).

UPDATE (originally covered 2026-06-28 as the NAIC breach): Nissan disclosed that current and former employees' data was exposed via CVE-2026-35273, the Oracle PeopleSoft PeopleTools pre-auth flaw exploited as a zero-day between 2026-05-27 and 2026-06-09 as part of the wider ShinyHunters campaign …

ctipilot v2 brief (migrated)
vulnerability01 Jul 04:41Zmulti-sourceOpen finding ↗

2026-06-29 · view entry permalink →

NOTABLECVE-2026-35273exploited

ShinyHunters / UNC6240 Oracle PeopleSoft campaign

The campaign behind the § 1 NAIC breach. GTIG/Mandiant attributes to UNC6240 an active zero-day exploitation of Oracle PeopleSoft (CVE-2026-35273) between May 27 and June 9, predating Oracle's advisory; staging environments deployed customised MeshCentral agents masquerading as cloud endpoints, then ran a per-victim [victim]_fanout.sh lateral-movement-and-defacement script (Google GTIG). ~300 PeopleSoft instances compromised, ~100 organisations notified, 68% higher education, with the University of Nottingham among the first named public victims (SecurityWeek). The status this week: NAIC confirmed (§ 1), and notifications are still landing, so more European education and public-finance victims are likely. The weekly lens: this is ShinyHunters operating as a zero-day-capable ERP attacker — a capability shift from the brand's 2021–2024 credential-stuffing persona. Outstanding question: which EU universities running PeopleSoft are in the un-notified tail.

The campaign behind the § 1 NAIC breach.

ctipilot v2 brief (migrated)
synthesis29 Jun 00:21Zmulti-sourceOpen finding ↗

2026-06-29 · view entry permalink →

HIGHCVE-2026-35273exploited

NAIC breached through an Oracle PeopleSoft zero-day; ShinyHunters dumps 3.1 TB and US rating-agency feeds stall

If you did nothing this week: any internet-reachable Oracle PeopleSoft instance is a live pre-auth foothold — the same zero-day path that put the US National Association of Insurance Commissioners into ShinyHunters' hands, and PeopleSoft is widely deployed across European public administration, higher education and HR/finance back offices. The W25 looking-ahead flagged that ShinyHunters PeopleSoft notifications were still landing and that EU universities were a probable next-named class; NAIC is the fresh high-profile confirmation that the campaign is still acquiring victims.

NAIC — the standard-setting body for all 50 US state insurance regulators — confirmed on 2026-06-26 that an unauthorised party reached its environment on June 11 via an Oracle PeopleSoft vulnerability, then pivoted from PeopleSoft to temporary access to data-storage areas. ShinyHunters claims 3.1 TB exfiltrated (TechRadar, Insurance Journal). The operational tell is the downstream impact NAIC itself disclosed: credit-rating agencies paused their data feeds and NAIC suspended assigning designations to insurer investments — a regulatory-process outage, not just a data-confidentiality event. This is the same PeopleSoft exploitation wave (CVE-2026-35273, the unauthenticated RCE in PeopleTools Environment Management) Google GTIG attributes to UNC6240/ShinyHunters and has been tracking against the education sector — 68% of identified targets were higher-education institutions; Treat any externally-reachable PeopleSoft portal (/PSEMHUB/, /PSIGW/HttpListeningConnector) as a hunt target, not a patch-later item. (daily 06-28)

Unauthorized access to a portion of the NAIC's environment was identified on June 11 via an Oracle PeopleSoft vulnerability. While in PeopleSoft, the unauthorized party was able to obtain information needed to gain temporary access to certain data storage areas.

Due to the incident, certain credit rating agencies have paused their data feeds and consequently, the NAIC has temporarily suspended assigning designations to insurer investments.

NAIC
synthesis29 Jun 00:20Zmulti-sourceOpen finding ↗

Earlier coverage (2)