Hackers are actively weaponizing an unpatched Oracle PeopleSoft zero-day. If your organization relies on core enterprise ERP systems, you're directly in the crosshairs. Throughout my career in cybersecurity, I've seen plenty of critical vulnerabilities. But watching attackers break straight into payroll, financial infrastructure, and proprietary records before a vendor patch even exists? That's the ultimate nightmare scenario—and honestly, nobody wants that two a.m. phone call.
The threat group ShinyHunters is leveraging CVE-2026-35273 in a widespread extortion campaign. They're targeting unpatched Oracle PeopleSoft deployments, gaining full unauthenticated remote code execution, and compromising backend ERP databases. What makes this so dangerous is how easily it slips past perimeter defenses and standard Web Application Firewalls. Attackers manipulate serialized requests inside PeopleSoft communication channels. That gives them an initial foothold to run arbitrary system commands, exfiltrate massive volumes of sensitive corporate data, and hit you with ransom demands.
Here are three critical breakdowns and immediate actions your SOC and engineering teams must take today.
First, understand the perimeter bypass. CVE-2026-35273 exploits an unauthenticated remote code execution flaw in PeopleSoft application gateways and Integration Broker endpoints. The exploit payloads blend seamlessly into normal enterprise transactions, so traditional signature-based WAFs often miss them completely. Once attackers secure remote execution, they pivot straight into your database tier to harvest employee records, banking details, and financial ledgers.
Second, deploy targeted threat hunting queries across your environment right now. Check your endpoint detection telemetry for abnormal process lineage. Specifically, hunt for Java processes running PeopleSoft or WebLogic services that spawn command interpreters like bash, sh, PowerShell, or cmd.exe. In your proxy and web access logs, look for anomalous POST requests aimed at PeopleSoft portal servlet paths with irregular header lengths or serialization markers. You must also flag any unexpected outbound network connections coming from your ERP application servers to unfamiliar external IP addresses.
Third, enforce immediate compensating mitigations while waiting for the vendor patch. Pull all internet-facing PeopleSoft instances from public exposure immediately and place them behind strict Zero Trust Network Access or VPN controls. Restrict administrative port access to trusted management subnets. Temporarily shut down unneeded Integration Broker services, and apply strict outbound egress filtering on your ERP database hosts to stop data exfiltration in its tracks.
Don't wait for an official patch to secure your critical infrastructure. Audit your external attack surface right now, run these hunting queries across your logs, and isolate exposed PeopleSoft endpoints immediately. Share this intelligence with your incident response and IT teams, and stay vigilant as this threat develops.