A critical zero-day vulnerability in Oracle’s PeopleSoft software has been exploited by the threat group known as ShinyHunters, impacting approximately 100 organizations and resulting in the theft of gigabytes of sensitive corporate data. The vulnerability, tracked as CVE-2026-35273, carries a CVSS severity rating of 9.8 out of 10 and allows for remote, unauthenticated server-side request forgery (SSRF) attacks, according to security researchers at Google’s Mandiant.
The exploitation campaign remained active for more than two weeks before Oracle issued a security advisory and provided interim mitigation steps. While Oracle has confirmed that the SSRF vulnerability is remotely exploitable, a permanent patch is currently pending. Victims of the breach have reported receiving extortion demands from the attackers, who are threatening to publish the stolen data unless a ransom is paid.
Understanding the CVE-2026-35273 Vulnerability
At its core, CVE-2026-35273 is a server-side request forgery (SSRF) flaw that enables unauthorized actors to manipulate the server into making requests to internal systems that are otherwise inaccessible from the public internet. By exploiting this mechanism, attackers can bypass perimeter defenses and interact directly with internal infrastructure, databases, and application servers within the PeopleSoft environment. The Oracle Critical Patch Update program typically governs the release of such fixes; however, in this instance, the company has prioritized the distribution of stopgap mitigations to limit the attack surface while developers finalize a comprehensive security update.
The severity of this flaw stems from its remote exploitability combined with the high-value nature of the data typically stored in PeopleSoft suites, which often include human resources, financial, and supply chain management records. Because the vulnerability allows for unauthenticated access, the barrier to entry for attackers is significantly lower than in scenarios requiring compromised user credentials. Organizations currently running affected versions of PeopleSoft are urged to consult the official Oracle Support portal for the most recent guidance on applying the temporary configuration changes provided by the vendor.
The Scope of the ShinyHunters Campaign
The threat group identified as ShinyHunters has targeted a diverse range of industries, successfully exfiltrating large volumes of data from approximately 100 distinct entities. According to reports from Mandiant, the group has transitioned from simple data theft to active extortion, contacting victim organizations to demand payment in exchange for the deletion of the stolen information. This tactic underscores a broader trend in the cybercriminal landscape, where the monetization of stolen data has shifted from underground marketplace sales to direct, high-pressure extortion of the affected companies.

The duration of the campaign—spanning more than 14 days prior to detection—provided the attackers with a substantial window to conduct reconnaissance and identify high-value targets within the compromised networks. The Cybersecurity and Infrastructure Security Agency (CISA) maintains databases of known exploited vulnerabilities, and while the specific details of the extortion demands remain under investigation, the operational pattern aligns with modern ransomware-as-a-service (RaaS) models. Organizations that suspect their systems have been accessed should review logs for anomalous outbound requests originating from their PeopleSoft application servers.
Mitigation and Protecting Enterprise Infrastructure
For IT administrators and security teams, the primary defense against this ongoing threat is the immediate implementation of the mitigation steps outlined by Oracle. Because a full patch is not yet available, teams must rely on network segmentation and strict egress filtering to prevent the PeopleSoft server from communicating with unauthorized internal or external endpoints. Limiting the application server’s ability to initiate connections to sensitive internal services can effectively neutralize the SSRF vector, even if the underlying software vulnerability remains unpatched.
Beyond technical mitigations, organizations are encouraged to monitor for unauthorized access attempts and to review their incident response plans. The National Institute of Standards and Technology (NIST) Cybersecurity Framework provides a structured approach for organizations to detect, respond to, and recover from such incidents. Companies that have identified signs of compromise are advised to engage with their legal counsel and cybersecurity insurance providers, as well as report the activity to national law enforcement agencies, such as the FBI’s Internet Crime Complaint Center (IC3).
Next Steps for Affected Organizations
Oracle has not yet announced a specific release date for the permanent patch for CVE-2026-35273, though updates are expected to be communicated through their standard security alert channels. Security professionals should monitor the National Vulnerability Database (NVD) for updates to the status of this CVE, as it will be updated once the vendor releases a definitive solution. Organizations should prioritize patching as soon as the update becomes available to restore full system integrity.
The situation remains fluid, and further information regarding the scope of the data theft may emerge as forensic investigations conclude. Readers are encouraged to check back for updates on the availability of the final patch and any additional guidance from security research firms. If you have information regarding the impact of this vulnerability or wish to discuss security mitigation strategies, please leave a comment below or share this report with your IT security team to ensure awareness across your organization.
Related reading