Despite ShinyHunters arrests after FBI jobs data breach, enterprises still have no answers about PeopleSoft risks
FBI breach confirms a second PeopleSoft zero-day. Oracle is silent. Enterprise users have no patch, no timeline, and no official guidance.

Why it matters
A confirmed breach of FBI employee data via PeopleSoft, combined with an unacknowledged second zero-day vulnerability and Oracle's refusal to comment, has left PeopleSoft customers exposed to an unpatchable flaw with no vendor mitigation path. This is not an isolated bug—it signals a pattern of critical preauth RCE flaws in the same product window, forcing security teams to choose between unproven workarounds and waiting for vendor acknowledgment that may not come.
The key facts
10 to knowShinyHunters claimed to exploit a second, previously undocumented PeopleSoft preauth RCE zero-day distinct from CVE-2026-35273
FBI confirmed the breach but provided no technical details on the vulnerability or attack vector
Oracle has not commented on the alleged second zero-day, issued no CVE, and no patch is available
CISA has not listed the flaw on its Known Exploited Vulnerabilities catalog
Analyst Frank Dickson (Dickson Research) recommended immediate mitigation: pull Environment Management Hub and Integration Broker off public internet, apply patch when available, hunt for web shells
Earlier PeopleSoft flaw (CVE-2026-35273) was bypassed by attackers using URL encoding (%50 for P) past WAF rules
IDC's Philip Harris noted that ShinyHunters claims to be exploiting the flaw against unnamed Fortune 500 targets
Jeff Valdes (Acceligence) stated Oracle's silence is unwarranted and customers lack operational security guidance without vendor confirmation
Previous ShinyHunters attack on PeopleSoft in June 2026 resulted in extortion campaigns long after Oracle claimed patches were released
ShinyHunters member arrested in Jordan cooperating with law enforcement; second member arrested by Dutch National Police a week prior
Go to the source
CIOcio.com
Publisher excerpt: The theft of FBI employee data by hacking group ShinyHunters, and the subsequent shutdown of the FBI’s Peoplesoft-based jobs portal, is causing concern for enterprise users of the Oracle product, with analysts recommending extreme measures in response. Law enforcement has made some progress in its…