CyberSecurityBoardThreat Intel · CVEs · Products
Attack Groups

ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities

June 25, 2026

The ShinyHunters extortion crew exploited an unpatched remote code execution vulnerability in Oracle PeopleSoft (CVE-2026-35273) to breach enterprise systems, primarily targeting universities. The flaw, rated 9.8 critical, requires no authentication and allows full server takeover via HTTP. Mandiant (tracking the group as UNC6240) confirmed active exploitation between May 27 and June 9, 2026. Attackers used exposed staging servers with custom MeshCentral agents disguised as Azure binaries and lateral-movement scripts. Over 100 organizations were notified; 68% were higher education institutions in the US. The University of Nottingham is a confirmed victim, with 455,000 unique emails leaked. Oracle’s advisory recommends disabling the Environment Management Hub or blocking external access to specific endpoints. ShinyHunters has shifted from SaaS attacks to on-premises ERP exploitation, raising concerns about broader targeting.

CVEs: CVE-2026-35273, CVE-2026-11645

Attack groups: ShinyHunters, UNC6240

Companies: Oracle, Mandiant, TrendAI

Products: Oracle PeopleSoft, PeopleTools, MeshCentral, Microsoft Azure