Critical RCE Vulnerability in Oracle PeopleSoft Exploited by SHADOW-AETHER-015
Article Content
- •CVE-2026-35273 allows unauthenticated RCE in Oracle PeopleSoft, affecting versions 8.61 and 8.62.
- •Exploitation was confirmed in a campaign targeting over 100 organizations, mainly in higher education.
- •The vulnerability is notable for its lack of observability, making detection challenging for defenders.
A pre-authentication remote code execution (RCE) vulnerability, CVE-2026-35273, was discovered in Oracle PeopleSoft PeopleTools, affecting versions 8.61 and 8.62. The vulnerability allows unauthenticated attackers to execute code within the application server's Java virtual machine (JVM) by exploiting the PSIGW gateway. Oracle issued a security alert on June 10, 2026, after TrendAI reported the vulnerability through its Zero Day Initiative. Mandiant confirmed that the vulnerability was actively exploited in a campaign named SHADOW-AETHER-015, targeting over 100 organizations, primarily in higher education, from May 27 to June 9, 2026. The exploitation method is particularly dangerous due to its lack of observability, as it executes code on server restart without generating outbound traffic. TrendAI has provided detection guidance for defenders to mitigate this threat. The situation remains critical as the vulnerability is currently being exploited in the wild.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Shadow-aether-015, Oracle and CVE-2026-35273 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…