INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

U.S. CISA Adds Oracle Vulnerability to Known Exploited Catalog

| 2026-06-13 09:19 CRITICAL HIGH
Executive Summary AI-generated
The threat landscape is increasingly complex, with numerous organizations falling victim to sophisticated cyber attacks. Mandiant's notification of over 100 US universities and colleges underscores the vulnerability of higher education institutions to exploitation by nation-state actors like ShinyHunters. The use of Oracle PeopleSoft Enterprise PeopleTools as a critical infrastructure component makes it an attractive target for attackers seeking remote code execution vulnerabilities, such as CVE-2026-35273. Organizations must prioritize robust security measures and threat awareness to mitigate these risks and protect against similar attacks in the future.
Technical Mitigations AI-generated
* Implement secure file server configurations, such as password protection and authentication requirements. * Regularly update and patch operating systems, applications, and services to ensure the latest security patches are applied. * Monitor network traffic for suspicious activity and implement intrusion detection and prevention systems (IDPS) or firewalls to block unauthorized access.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-35273CVE-2026-35273
Target & Sectors
NORTH_AMERICA NORTH_AMERICA technologytechnology
Incident Timeline
‎May 27, 2026
Threat actors exploited a known vulnerability in Oracle PeopleSoft Enterprise PeopleTools, which was added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) catalog of Known Exploited Vulnerabilities on May 27, 2026.
‎between May 27, 2026
Threat actors exploited CVE-2026-35273, a critical remote code execution vulnerability in Oracle PeopleSoft Enterprise PeopleTools.
vulnerability CVE-2026-35273
vulnerability CVSS score of 9.8
tactic Remote Code Execution
‎May 27
The attackers installed MeshCentral version 1.1.59 on May 27 at 22:14 UTC.
infrastructure 1.1.59
organisation UTC
‎June 9, 2026
Threat actors exploited CVE-2026-35273, a critical remote code execution vulnerability in the Environment Management component of U.S. CISA's Oracle PeopleSoft Enterprise PeopleTools.
vulnerability CVE-2026-35273
vulnerability CVSS score of 9.8
tactic Remote Code Execution
organisation Google
‎June 10, 2026
The attackers exploited a zero-day vulnerability in Oracle PeopleSoft Enterprise PeopleTools 8.61 and 8.62 by using the MeshCentral CLI tool to run commands on compromised endpoints, mapping configurations and reading sensitive files.
organisation Oracle’s
organisation WebLogic
organisation ShinyHunters
infrastructure 8.61
infrastructure 8.62
organisation PeopleTools
organisation Oracle
infrastructure Windows
organisation Microsoft Azure
organisation CLI
organisation WebLogic XML
organisation IP
organisation Microsoft Azure NetApp Files
organisation MeshCentral
organisation PeopleSoft
organisation SSH
organisation The  University of Nottingham
‎June 11
ShinyHunters used a known exploit of the Oracle PeopleSoft Enterprise PeopleTools vulnerability to target Mandiant.
attribution ShinyHunters
attribution Mandiant
attribution Google’s Threat Intelligence Group
‎May 27 to June 9
The U.S. CISA added the Oracle PeopleSoft Enterprise PeopleTools zero-day flaw to its Known Exploited Vulnerabilities catalog from May 27 to June 9.
‎2026/06/13
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a remote code execution vulnerability in Oracle PeopleSoft's Environment Management component to its Known Exploited Vulnerabilities catalog due to the presence of this flaw in 68% of over 100 organizations, including universities and colleges primarily located in the United States.
organisation Mandiant
victims 100 organizations
organisation Oracle PeopleSoft
organisation Oracle PeopleSoft’s Environment Management
organisation the Environment Management Hub
‎June 15, 2026
Threat actors used a known exploit of Oracle PeopleSoft Enterprise PeopleTools to target U.S. federal agencies, which CISA ordered to fix by June 15, 2026.
Tactical Metrics
Metrics
victims
100
Organizations
Metrics
infrastructure
‎8.61
Software Version
Metrics
infrastructure
‎8.62
Software Version
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎1.1.59
Software Version