CVE-2026-35273: An actively exploited critical RCE flaw in Oracle PeopleSoft Enterprise PeopleTools

23 Sep 2026

Security researchers have reported an actively exploited critical vulnerability affecting Oracle PeopleSoft PeopleTools and PeopleSoft Enterprise.

 

In this blog, we will understand what the flaw (CVE-2026-35273) is about, the threat it poses, and what organizations can do to defend against it.

About the vulnerabilities

Vendor/ Component impacted 

Threat Type 

CVE identifier/ 
CVSS 

Affected components 

Affected versions 

Oracle Corporation + PeopleSoft PeopleTools 

Remote Code Execution 

CVE-2026-91843/ 9.8 
(Critical) 

Updates Environment Management / Environment Management Hub (EMHub) 

Oracle PeopleSoft Enterprise PeopleTools 8.61 
 
– Oracle PeopleSoft Enterprise PeopleTools 8.62 

 

Threat actor 

Exploitation status 

Attack vector 

UNC6240/ShinyHunters 

Actively exploited as zero-day 

Network/HTTP 

 

The flaw was initially disclosed on June 10, 2026, after Google Threat Intelligence reported exploitation between May 27 and June 9, 2026, as a zero-day.

 

ShinyHunters’ recent claim of compromising FBI systems through the exploitation of the flaw has raised concerns about continued risk to organizations running internet-facing Oracle PeopleSoft environments.

CVE-2026-35273 An actively exploited critical RCE flaw in Oracle PeopleSoft Enterprise PeopleTools

Threat posed by the vulnerability

By successfully exploiting the vulnerability, an attacker can:

 

  • Execute arbitrary code on the affected PeopleSoft server.
  • Take control of the PeopleSoft environment.
  • Establish persistence on compromised servers.
  • Conduct reconnaissance of internal systems and configurations.
  • Move laterally to other systems within the organization’s environment.
  • Access and potentially exfiltrate sensitive business, employee, financial, or student information.
  • Deploy additional tooling or malicious files on compromised PeopleSoft infrastructure.

SharkStriker’s recommendations

  • Apply Oracle’s security fix for CVE-2026-35273 immediately.
  • If patching cannot be performed immediately, follow Oracle’s mitigation guidance and disable the Environment Management Hub (EMHub) service where possible.
  • For single-server configurations, consider removing the PSEMHUB application as recommended by Oracle.
  • If EMHub cannot be disabled, restrict external access to /PSEMHUB/* and /PSIGW/HttpListeningConnector at the firewall or network perimeter.
  • Review PeopleSoft/PIA WebLogic access logs for suspicious external requests, particularly POST requests to /PSEMHUB/hub and /PSIGW/HttpListeningConnector.
  • Review the PeopleSoft web-tier filesystem for unexpected .jsp files and suspicious files or directories within the PSEMHUB application paths.
  • Monitor outbound network connections originating from PeopleSoft servers for unusual or unauthorized destinations.
  • Review authentication and system activity for signs of lateral movement or unauthorized administrative access.
  • Ensure PeopleSoft systems are running supported versions and apply Oracle Critical Patch Updates and Security Alerts without delay.
  • If indicators of compromise are identified, immediately initiate incident response and investigate the affected PeopleSoft environment for potential data access or exfiltration.

Get in Touch With us

We have explored what risk tolerance and risk appetite are and how important they are together in helping businesses align cybersecurity with their business goals. It can help CISOs, and C-suite make informed investment decisions for cybersecurity.

LEARN MORE