Critical RCE Vulnerability in Oracle PeopleSoft Exploited by SHADOW-AETHER-015
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A pre-authentication remote code execution (RCE) vulnerability, CVE-2026-35273, was discovered in Oracle PeopleSoft PeopleTools, affecting versions 8.61 and 8.62. The vulnerability allows unauthenticated attackers to execute code within the application server's Java virtual machine (JVM) by exploiting the PSIGW gateway. Oracle issued a security alert on June 10, 2026, after TrendAI reported the vulnerability through its Zero Day Initiative. Mandiant confirmed that the vulnerability was actively exploited in a campaign named SHADOW-AETHER-015, targeting over 100 organizations, primarily in higher education, from May 27 to June 9, 2026. The exploitation method is particularly dangerous due to its lack of observability, as it executes code on server restart without generating outbound traffic. TrendAI has provided detection guidance for defenders to mitigate this threat. The situation remains critical as the vulnerability is currently being exploited in the wild.
Key Points: • CVE-2026-35273 allows unauthenticated RCE in Oracle PeopleSoft, affecting versions 8.61 and 8.62. • Exploitation was confirmed in a campaign targeting over 100 organizations, mainly in higher education. • The vulnerability is notable for its lack of observability, making detection challenging for defenders.