Enterprise HR software is supposed to be the most boring corner of the internet — the digital equivalent of a filing cabinet nobody thinks about until payroll runs late. Oracle PeopleSoft just had a very different kind of moment: it became the entry point for one of the year's largest breach sprees.
One HTTP Request, Total Server Takeover
The culprit is CVE-2026-35273, a critical, CVSS 9.8 unauthenticated remote code execution flaw in the Environment Management Hub component of PeopleSoft PeopleTools 8.61 and 8.62. No login, no user interaction, no elaborate social engineering required — a single HTTP request to an exposed endpoint hands an attacker full control of the server.
The extortion group ShinyHunters, tracked by Google's Mandiant team as UNC6240, exploited it between May 27 and June 9, 2026, hitting more than 100 organizations across roughly 300 instances. Universities and other higher-ed institutions bore the brunt, with attackers walking away with payroll records, financial aid data, immigration documents, health information, and student PII.
Oracle's Advisory Showed Up Late to Its Own Party
Here's the part that should sting more than the vulnerability itself: Oracle didn't publish its security advisory until June 10 — a full day after ShinyHunters had already started publishing stolen data. That's not a patch gap, that's a patch gap with the lights off and nobody home.
The real issue isn't just one buggy endpoint — it's that PeopleSoft is exactly the kind of "we set it up in 2014 and nobody's touched it since" system that sits quietly exposed to the internet at hundreds of institutions, and attackers know it. Mandiant had to proactively notify affected orgs because plenty of them likely didn't even know their instance was reachable, let alone vulnerable.
If your HR system has been running uninterrupted since the Obama administration, today's a great day to ask IT an uncomfortable question.
Source: Arctic Wolf