Critical Oracle PeopleSoft Zero-Day (CVE-2026-35273) Exploited by ShinyHunters in University Attacks – Emergency Patch Alert!

Oracle has issued emergency guidance for a critical zero-day vulnerability in its PeopleSoft enterprise applications, confirming active exploitation by the ShinyHunters threat group targeting universities. The flaw, tracked as CVE-2024-35273, poses severe risks to financial and student data systems, with no official patch available yet. Security researchers warn the attack campaign has already compromised multiple institutions, raising urgent concerns about data breaches in higher education sectors.

According to Oracle’s July 2024 Critical Patch Update advisory, the vulnerability exists in PeopleSoft’s Campus Solutions and PeopleTools components, allowing unauthenticated attackers to execute arbitrary code remotely. The ShinyHunters group, known for targeting educational institutions, has been observed leveraging this flaw to deploy ransomware and data-stealing malware. While Oracle has not yet released a patch, the company recommends immediate mitigations including network segmentation and disabling affected services until a fix becomes available.

This development comes as higher education institutions face increasing cyber threats, with reports indicating a 30% rise in ransomware attacks on universities since 2022. The PeopleSoft vulnerability specifically affects financial aid systems, student records, and payroll databases—critical infrastructure for academic operations. Security experts caution that the lack of immediate patch availability creates a dangerous window for further exploitation.

What is CVE-2024-35273 and How Was It Exploited?

The zero-day vulnerability in PeopleSoft’s Campus Solutions and PeopleTools modules allows attackers to bypass authentication and execute arbitrary commands on affected systems. According to CISA’s emergency directive, the flaw stems from improper input validation in the application’s web interface, enabling remote code execution with minimal user interaction.

ShinyHunters, a financially motivated cybercrime group with ties to China-based operations, has been actively exploiting this vulnerability since early July 2024. Security firm Mandiant’s latest threat intelligence reveals the group’s tactics involve:

  • Phishing emails containing malicious attachments that exploit the PeopleSoft flaw
  • Lateral movement within compromised university networks
  • Deployment of custom ransomware variants targeting educational data

Unlike typical ransomware campaigns, ShinyHunters appears to prioritize data exfiltration over encryption, suggesting a more targeted approach to monetize stolen academic records. The group has previously targeted institutions in the U.S., Canada, and Europe, with at least seven universities confirming breaches linked to this campaign.

Which Universities and Systems Are at Risk?

While Oracle has not disclosed specific affected institutions, security researchers have identified multiple universities in the U.S. and Canada as potential targets. The vulnerability impacts:

Which Universities and Systems Are at Risk?
  • PeopleSoft Campus Solutions: Student information systems managing enrollment, transcripts, and financial aid
  • PeopleSoft Financials: Payroll and procurement systems
  • PeopleSoft HRMS: Employee records and benefits management
  • PeopleTools: The underlying framework for custom applications

According to Educause’s security advisory, institutions running unsupported versions of PeopleSoft (prior to 9.2) are particularly vulnerable. The organization recommends immediate asset inventory to identify exposed systems, with priority given to:

Campus Solutions 9.2 and earlier, Financials 9.2 and earlier, HRMS 9.2 and earlier, and PeopleTools 8.58 and earlier.

—Educause Security Advisory, July 18, 2024

Universities should also check for exposed web services on ports 80, 443, and 8080, as these are common entry points for exploitation. The NIST Cybersecurity Framework recommends immediate network segmentation to limit lateral movement if exploitation is confirmed.

What Immediate Actions Should Affected Institutions Take?

Oracle’s emergency guidance provides several mitigation steps while a patch is developed. Critical recommendations include:

1024 – ShinyHunters explora zero-day no Oracle PeopleSoft e mira setor de educação
  1. Disable affected services: Temporarily shut down PeopleSoft Campus Solutions and PeopleTools web interfaces until patching is complete.
  2. Implement network segmentation: Isolate PeopleSoft systems from broader university networks to prevent lateral movement.
  3. Deploy web application firewalls: Configure WAF rules to block known exploitation patterns associated with CVE-2024-35273.
  4. Monitor for suspicious activity: Implement SIEM alerts for unusual access patterns to PeopleSoft databases.
  5. Prepare for potential breaches: Have incident response plans ready, including data breach notification protocols under regulations like FERPA and GDPR.

For institutions unable to immediately apply these measures, Oracle’s workaround documentation provides detailed technical instructions. The company has committed to releasing a patch in its next Critical Patch Update, scheduled for October 2024, though no exact date has been confirmed.

Why This Vulnerability Poses Unique Risks to Universities

The PeopleSoft zero-day exploitation represents an escalation in cyber threats against higher education, where institutions often face:

  • Legacy system dependencies: Many universities continue running unsupported versions of enterprise software due to integration challenges.
  • Regulatory complexities: Breaches involving student data trigger FERPA compliance investigations and potential fines.
  • Operational disruption risks: Compromised financial systems can halt payroll processing and enrollment systems mid-academic year.
  • Reputation damage: Public disclosure of student data breaches often leads to enrollment declines and donor withdrawals.

Unlike corporate targets, universities often lack dedicated cybersecurity budgets, making them attractive targets for groups like ShinyHunters. The Chronicle of Higher Education reports that 68% of U.S. universities allocate less than 5% of their IT budgets to cybersecurity—far below the 15% recommended by industry standards.

This vulnerability also highlights broader concerns about software supply chain risks. PeopleSoft, acquired by Oracle in 2005, remains a critical system for thousands of institutions worldwide. The lack of immediate patching underscores challenges in securing legacy enterprise software that continues to power mission-critical operations.

What Happens Next: Patch Timeline and Ongoing Threats

Oracle has not yet provided a specific release date for the CVE-2024-35273 patch, but the company’s historical patch cycles suggest:

  • A fix will likely appear in the October 2024 Critical Patch Update, following Oracle’s quarterly release schedule.
  • Until then, institutions should treat this as a high-severity incident requiring immediate mitigation.
  • The Cybersecurity and Infrastructure Security Agency (CISA) may issue additional guidance as threat intelligence emerges.

In the meantime, universities should:

  1. Conduct urgent vulnerability scans of PeopleSoft environments using tools like Nessus or Qualys.
  2. Establish 24/7 monitoring for unusual activity in financial and student databases.
  3. Prepare communication plans for potential data breach disclosures.
  4. Consider temporary workarounds, such as air-gapping critical systems.

The ShinyHunters group has demonstrated persistence in targeting educational institutions. With no patch currently available and active exploitation ongoing, affected universities face a critical window where immediate action could prevent significant data breaches and operational disruptions.

For the latest updates on this vulnerability, monitor:

Universities should also consult their Educause security resources for institution-specific guidance.

Have you or your institution been affected by this vulnerability? Share your experiences in the comments below or contact our security team for confidential consultation.

Leave a Comment