Skip to content
vulnerabilityCVEcredential-theftVulnerability Research

Oracle patches the flaw that let ShinyHunters breach 100 organizations

3 min read
Share

๐ŸŸก Disclosed and patched | CVSS Critical | Oracle July 2026 CPU

A patch that arrives after the damage is done

Oracle's July 2026 Critical Patch Update included a fix for CVE-2026-35273, an authentication bypass in PeopleSoft that ShinyHunters used to breach more than 100 organizations earlier this year. The patch is important and organizations should apply it immediately. But understanding how this vulnerability was discovered and exploited reveals a structural problem in how Oracle's quarterly patch cadence interacts with the reality of active threat actor operations.

What the vulnerability is

CVE-2026-35273 is an authentication bypass in Oracle PeopleSoft's web services layer. An unauthenticated attacker could access PeopleSoft campus and enterprise services without valid credentials by manipulating token validation logic. Once authenticated, the attacker gains access to HR, finance, and student data depending on which PeopleSoft modules are deployed.

How ShinyHunters exploited it

ShinyHunters discovered or acquired CVE-2026-35273 and used it as the primary entry vector for a mass exploitation campaign that ran for several weeks before Oracle's July CPU closed the window. The group targeted universities, healthcare systems, and mid-market enterprises running publicly accessible PeopleSoft deployments. Confirmed victim data includes social security numbers, financial records, and student enrollment information, with estimates suggesting exposure of over one million individual records across all victims.

What the July CPU addresses

Oracle's July 2026 CPU patches CVE-2026-35273 with a CVSS score reflecting critical severity. The fix corrects the token validation flaw that enabled the authentication bypass. Organizations that apply the patch will close the initial access vector ShinyHunters used. The patch does not, however, address data already exfiltrated during the exploitation window.

Why you should still treat your environment as potentially compromised

Any organization running a publicly accessible PeopleSoft deployment that did not apply a fix prior to this CPU cycle should assume that its instance was scanned and potentially compromised. ShinyHunters' campaigns are automated at scale. The absence of a known breach notice is not evidence that data was not accessed. Recommended steps: apply the July CPU patch now, review PeopleSoft access logs for the period from June 15 through the patch application date, check for unexpected data export jobs or bulk query activity, and assess whether notification obligations under applicable breach notification laws apply.

The durable lesson

Oracle's quarterly patch cycle creates a predictable window between the time a vulnerability enters the wild and the time it receives an official fix. Threat actors who identify or acquire zero-days in Oracle products know exactly how long that window is. Organizations with internet-facing Oracle deployments should have a process for applying emergency patches outside the CPU schedule when active exploitation is confirmed, and should treat public-facing PeopleSoft, E-Business Suite, and similar platforms with the same urgency as internet-facing web servers.

Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if your organization is assessing PeopleSoft exposure or breach notification obligations.