ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns
Mandiant warns that ShinyHunters is exploiting a known Oracle PeopleSoft vulnerability (CVE-2026-35273) despite patches and workarounds. The group has targeted multiple sectors, including education, healthcare, and government. Oracle users are advised to review logs and prepare for potential extortion. ShinyHunters recently claimed an FBI breach via this vulnerability.
How this was made

The 30-second read
Why it matters
The renewed exploitation raises immediate security concerns for Oracle customers and could drive short‑term stock pressure while boosting demand for security solutions.
Market read
First report of a revived exploit against a major enterprise platform; may prompt investors to reassess Oracle's risk exposure.
What to watch
The exploit may primarily affect smaller, less‑resourced organizations, limiting broader market fallout.
Background
Oracle PeopleSoft is a core ERP system used across government, education, and healthcare. A zero‑day vulnerability (CVE-2026-35273) was patched in June 2026, but threat actors are now targeting entities that only applied workarounds.
Ticker impact
Mandiant reports that ShinyHunters has resumed exploiting the Oracle PeopleSoft CVE-2026-35273 vulnerability after the June patch, targeting organizations that only applied workarounds.
downward pressure as investors price in exposure to the newly‑active exploit.
The vulnerability affects a widely used enterprise suite; renewed exploitation signals a fresh threat vector that could lead to breach costs and reputational damage.
Market effects
Enterprise software and cybersecurity vendors may see increased demand for security services.
U.S. and global enterprises using PeopleSoft could reassess vendor risk.
Potential ripple effect on tech stocks with similar exposure.
Counterpoint
Oracle's swift patch and strong balance sheet may limit long‑term impact on the stock.
Key entities
- companyOracle
U.S.-listed provider of PeopleSoft ERP software.
- hacking groupShinyHunters
Cyber‑crime group exploiting the PeopleSoft vulnerability.
- security firmMandiant
Researcher reporting the renewed exploitation.



