Oracle flags critical vulnerability as researchers identify 100+ potential targets - Inspirepreneur Magazine

Oracle flags critical vulnerability as researchers identify 100+ potential targets

P
Pooja Malik
Jun 12, 2026 10:32 AM IST
Category Technology

Synopsis

Oracle has warned customers about a critical PeopleSoft vulnerability after researchers linked the flaw to attacks targeting more than 100 organizations. Most identified targets were in higher education, while exposed systems were also found in Australia, Canada and the United Kingdom, prompting immediate security reviews.

Customers have been issued a high-priority alert by Oracle following a critical vulnerability in its PeopleSoft system that has been linked to attacks on over 100 businesses, universities and government organizations.

The vulnerability, officially called CVE-2026-35273, affects PeopleTools versions 8.61 and 8.62, which provide the framework for Oracle PeopleSoft applications. Oracle stated the flaw could be exploited by attackers over the internet without authorisation and enable malicious code to be run on compromised systems.

Security company Mandiant claims that the vulnerability was already being exploited from 27 May to 9 June, prior to Oracle announcing it. The attacks have been linked to the hacking group ShinyHunters.

01
Chapter one

Universities are the main target

The researchers alerted more than 100 organizations that may have had vulnerable internet-facing systems. Whilst most were based in the United States, they also discovered exposed systems in other countries including Australia, Canada and the United Kingdom.

The higher education sector constituted around 68% of the targeted organizations, according to Mandiant. Universities commonly use Oracle PeopleSoft for student records management, human resources, procurement, human resources and financial management, making it an integral part of its administration.

Despite some organizations successfully repelling the attacks or taking security measures prior to any data access, some have had its data compromised by the flaw.

02
Chapter two

Organizations under pressure to respond

Oracle has designated the vulnerability as a score of 9.8/10 on the Common Vulnerability Scoring System scale, indicating an extreme risk issue. Oracle issued a dedicated security alert, advising clients to apply mitigation measures at the earliest opportunity.

This issue comes at a time when many businesses are experiencing increased pressure to provide sufficient security for all enterprise software systems that store sensitive operational and business data. As per IBM's 2024 Cost of a Data Breach Report, data breaches worldwide reached an average cost of US$4.88 million, their highest value to date.

Oracle announced its 2025 fiscal revenues as approximately US$57.4 billion. Enterprise applications continue to form the backbone of its software offerings and Oracle has not provided an estimate of the number of customers affected by the exploit.


Follow Inspirepreneur Magazine for daily global business news.

P
Written by Pooja Malik

Pooja Malik is a business journalist with over six years of experience covering startups, entrepreneurship, and emerging trends. She has previously worked with leading media platforms such as YourStory Media and BW BusinessWorld, where she reported on business, policy, and market developments. Currently, she serves as Editor at The Inspirepreneur Magazine, where she writes and edits stories across business, lifestyle, and travel, with a focus on clarity, accuracy, and reader relevance.