Skip to content
Critical RCE Vulnerability in Oracle PeopleSoft Exploited by SHADOW-AETHER-015

Critical RCE Vulnerability in Oracle PeopleSoft Exploited by SHADOW-AETHER-015

First seen 18 Jun 2026, 12:57 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 19, 2026 at 12:27 UTC
  • CVE-2026-35273 allows unauthenticated RCE in Oracle PeopleSoft, affecting versions 8.61 and 8.62.
  • Exploitation was confirmed in a campaign targeting over 100 organizations, mainly in higher education.
  • The vulnerability is notable for its lack of observability, making detection challenging for defenders.

A pre-authentication remote code execution (RCE) vulnerability, CVE-2026-35273, was discovered in Oracle PeopleSoft PeopleTools, affecting versions 8.61 and 8.62. The vulnerability allows unauthenticated attackers to execute code within the application server's Java virtual machine (JVM) by exploiting the PSIGW gateway. Oracle issued a security alert on June 10, 2026, after TrendAI reported the vulnerability through its Zero Day Initiative. Mandiant confirmed that the vulnerability was actively exploited in a campaign named SHADOW-AETHER-015, targeting over 100 organizations, primarily in higher education, from May 27 to June 9, 2026. The exploitation method is particularly dangerous due to its lack of observability, as it executes code on server restart without generating outbound traffic. TrendAI has provided detection guidance for defenders to mitigate this threat. The situation remains critical as the vulnerability is currently being exploited in the wild.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 91d ago How this analysis works

Timeline

2026-06-10
Oracle issues security alert for CVE-2026-35273
Oracle disclosed a critical RCE vulnerability in PeopleSoft PeopleTools, prompting urgent action.
Trendmicro
2026-06-11
CVE-2026-35273 published
The vulnerability was officially published, detailing its critical nature and potential impact.
Trendmicro
2026-06-12
CVE-2026-35273 added to CISA KEV
The vulnerability was recognized by CISA as actively exploited, increasing its urgency.
Trendmicro
2026-06-12
First public PoC released
A proof of concept for the vulnerability was made public, raising concerns about widespread exploitation.
Trendmicro
2026-06-18
TrendAI publishes detailed analysis
TrendAI released a comprehensive analysis of the exploitation chain and provided detection guidance for defenders.
Trendmicro

More articles in this cluster (5)

Following this threat?

Track Shadow-aether-015, Oracle and CVE-2026-35273 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed