Critical RCE Vulnerability in Oracle PeopleSoft Exploited by SHADOW-AETHER-015

Critical RCE Vulnerability in Oracle PeopleSoft Exploited by SHADOW-AETHER-015

First seen 18 Jun 2026, 12:57 UTC Feeds.TrendmicroTrendmicro 100% similarity 78.0

Article Content

Browse articles
ThreatCluster

A pre-authentication remote code execution (RCE) vulnerability, CVE-2026-35273, was discovered in Oracle PeopleSoft PeopleTools, affecting versions 8.61 and 8.62. The vulnerability allows unauthenticated attackers to execute code within the application server's Java virtual machine (JVM) by exploiting the PSIGW gateway. Oracle issued a security alert on June 10, 2026, after TrendAI reported the vulnerability through its Zero Day Initiative. Mandiant confirmed that the vulnerability was actively exploited in a campaign named SHADOW-AETHER-015, targeting over 100 organizations, primarily in higher education, from May 27 to June 9, 2026. The exploitation method is particularly dangerous due to its lack of observability, as it executes code on server restart without generating outbound traffic. TrendAI has provided detection guidance for defenders to mitigate this threat. The situation remains critical as the vulnerability is currently being exploited in the wild.

Key Points: • CVE-2026-35273 allows unauthenticated RCE in Oracle PeopleSoft, affecting versions 8.61 and 8.62. • Exploitation was confirmed in a campaign targeting over 100 organizations, mainly in higher education. • The vulnerability is notable for its lack of observability, making detection challenging for defenders.

ThreatCluster AI How this analysis works

Timeline

2026-06-10
Oracle issues security alert for CVE-2026-35273
Oracle disclosed a critical RCE vulnerability in PeopleSoft PeopleTools, prompting urgent action.
Trendmicro
2026-06-11
CVE-2026-35273 published
The vulnerability was officially published, detailing its critical nature and potential impact.
Trendmicro
2026-06-12
CVE-2026-35273 added to CISA KEV
The vulnerability was recognized by CISA as actively exploited, increasing its urgency.
Trendmicro
2026-06-12
First public PoC released
A proof of concept for the vulnerability was made public, raising concerns about widespread exploitation.
Trendmicro
2026-06-18
TrendAI publishes detailed analysis
TrendAI released a comprehensive analysis of the exploitation chain and provided detection guidance for defenders.
Trendmicro

Community

Browse all →