Oracle flags critical vulnerability as researchers identify 100+ potential targets
Synopsis
Oracle has warned customers about a critical PeopleSoft vulnerability after researchers linked the flaw to attacks targeting more than 100 organizations. Most identified targets were in higher education, while exposed systems were also found in Australia, Canada and the United Kingdom, prompting immediate security reviews.
Customers have been issued a high-priority alert by Oracle following a critical vulnerability in its PeopleSoft system that has been linked to attacks on over 100 businesses, universities and government organizations.
The vulnerability, officially called CVE-2026-35273, affects PeopleTools versions 8.61 and 8.62, which provide the framework for Oracle PeopleSoft applications. Oracle stated the flaw could be exploited by attackers over the internet without authorisation and enable malicious code to be run on compromised systems.
Security company Mandiant claims that the vulnerability was already being exploited from 27 May to 9 June, prior to Oracle announcing it. The attacks have been linked to the hacking group ShinyHunters.
Universities are the main target
The researchers alerted more than 100 organizations that may have had vulnerable internet-facing systems. Whilst most were based in the United States, they also discovered exposed systems in other countries including Australia, Canada and the United Kingdom.
The higher education sector constituted around 68% of the targeted organizations, according to Mandiant. Universities commonly use Oracle PeopleSoft for student records management, human resources, procurement, human resources and financial management, making it an integral part of its administration.
Despite some organizations successfully repelling the attacks or taking security measures prior to any data access, some have had its data compromised by the flaw.
Organizations under pressure to respond
Oracle has designated the vulnerability as a score of 9.8/10 on the Common Vulnerability Scoring System scale, indicating an extreme risk issue. Oracle issued a dedicated security alert, advising clients to apply mitigation measures at the earliest opportunity.
This issue comes at a time when many businesses are experiencing increased pressure to provide sufficient security for all enterprise software systems that store sensitive operational and business data. As per IBM's 2024 Cost of a Data Breach Report, data breaches worldwide reached an average cost of US$4.88 million, their highest value to date.
Oracle announced its 2025 fiscal revenues as approximately US$57.4 billion. Enterprise applications continue to form the backbone of its software offerings and Oracle has not provided an estimate of the number of customers affected by the exploit.
Follow Inspirepreneur Magazine for daily global business news.
Pooja Malik is a business journalist with over six years of experience covering startups, entrepreneurship, and emerging trends. She has previously worked with leading media platforms such as YourStory Media and BW BusinessWorld, where she reported on business, policy, and market developments. Currently, she serves as Editor at The Inspirepreneur Magazine, where she writes and edits stories across business, lifestyle, and travel, with a focus on clarity, accuracy, and reader relevance.
You Might Also Like
Decisiveness Under Pressure: Sharpening Your Judgement In Business Scenarios
Chinese AI firms launch new models during Spring Festival push