ShinyHunters’ exploitation of a new PeopleSoft zero-day hole threatens to change enterprise risk dynamics
PeopleSoft shops face a potentially unpatched zero-day with no vendor guidance. Here's what enterprise security teams should do now.

Why it matters
A claimed new PeopleSoft preauth RCE zero-day, allegedly used by ShinyHunters against FBI systems and Fortune 500 targets, exposes a pattern of critical flaws in Oracle's enterprise software. Unlike the June CVE, this one remains unacknowledged by Oracle, leaving customers without mitigation guidance while waiting for confirmation that may not come.
The key facts
17 to knowShinyHunters claims a new, distinct PeopleSoft preauth RCE zero-day separate from CVE-2026-35273 (June flaw)
FBI confirmed breach of FBI employee data but did not disclose attack vector
No CVE assigned; not on CISA Known Exploited Vulnerabilities catalog; Oracle has not commented
Claimed to be actively exploited against unnamed Fortune 500 targets
June PeopleSoft zero-day CVE-2026-35273: many organizations bypassed patching with WAF rules, which attackers defeated by encoding 'P' as '%50' in the URL path
Frank Dickson (Dickson Research): recommends immediate removal of Environment Management Hub and Integration Broker from public internet; search logs for encoded PSEMHUB paths; implement Mandiant report recommendations from late September
Philip Harris (IDC): cautioned that zero-day claim is from threat actor only, not independent forensic confirmation or Oracle acknowledgment
Jeff Valdes (Acceligence): criticized Oracle's silence; customers need clarity on whether original guidance is sufficient, additional mitigations needed, and whether configurations materially increase exposure
Suspected ShinyHunters member arrested by FBI (reported Saturday by Reuters); cooperating with law enforcement
ShinyHunters claims exploitation of a new PeopleSoft preauth RCE zero-day, distinct from CVE-2026-35273 (June 2026)
FBI breach of employee data confirmed by FBI; attack vector not disclosed by law enforcement
Zero-day claim sourced only from threat actor; no CVE assigned, not on CISA Known Exploited Vulnerabilities catalog, Oracle has not commented
Analyst Frank Dickson recommends: pull Environment Management Hub and Integration Broker from public internet, apply patch when available, search logs for encoded variants, rotate credentials if web shell detected
IDC analyst Philip Harris notes pattern risk: if real, a second critical unpatched preauth RCE in same window suggests recurring exposure, not isolated bug
Consultant Jeff Valdes criticizes Oracle silence: customers lack clarity on whether original guidance remains sufficient, additional mitigations needed, configuration risk increases
Prior June 2026 PeopleSoft zero-day exploited by ShinyHunters; organizations mitigated with WAF rules, attackers bypassed by encoding single character ('%50' for 'P')
FBI suspect arrested, cooperating with law enforcement; analysts downplay implications of single arrest given group's persistence
Go to the source
CIOcio.com
Publisher excerpt: A recent compromise of PeopleSoft by hacking group ShinyHunters is causing new concerns for enterprise users of the Oracle product, with analysts recommending extreme measures in response. Law enforcement has made some progress in its pursuit of the cyber criminals involved. On Saturday, Reuters…