CVE-2026-35273: Oracle PeopleSoft PeopleTools Vuln Exploited by ShinyHunters

Last Updated: 2026-06-12T20:05:11Z

What’s Happening

CVE-2026-35273, a CVSSv3 9.8 severity vulnerability allows “takeover” or “code execution.” No details on mechanism as yet.

https://www.oracle.com/security-alerts/alert-cve-2026-35273.html

The CVE listing shows the CWE as CWE-308, or “Missing Authentication for Critical Function.” So presumably an auth bypass or Broken Function Level Authorization on an API endpoint.

The Register reports that ShinyHunters credit this vulnerability for the breach of the University of Nottingham, along with many other organizations.

Actions

Apply available patches to PeopleTools instances ASAP.

Indicators of Compromise

Hunt for these IoCs from Palo Alto.

Value Type Description
45.135.232[.]140 IPv4 C2 / infrastructure
91.215.85[.]101 IPv4 C2 / infrastructure
108.174.202[.]99 IPv4 C2 / infrastructure
142.11.200[.]186 IPv4 C2 / infrastructure
142.11.200[.]187 IPv4 C2 / infrastructure
142.11.200[.]188 IPv4 C2 / infrastructure
142.11.200[.]189 IPv4 C2 / infrastructure
142.11.200[.]190 IPv4 C2 / infrastructure
176.120.22[.]24 IPv4 C2 / infrastructure
207.89.18[.]29 IPv4 C2 / infrastructure
azurenetfiles[.]net Domain C2 / infrastructure
bmwebhost[.]com Domain C2 / infrastructure
onlinepaymentterminal[.]com Domain C2 / infrastructure
paymentprocessterminal[.]com Domain C2 / infrastructure
techvertix[.]com Domain C2 / infrastructure
78166e8cd026f6f7fc612244e587c2565487f2635fc3d704987972ede619aef9 SSH Key Fingerprint Attacker SSH key fingerprint
9098906159e0e4c845eb918886fadc2723f2a321281b8003e471f09140321f91 SHA256 Malware sample
c7e9332731b06644fc73e0046a2a89eaa59b09f54250e9bd622467187351711f SHA256 Malware sample
d65f14e5652a4330354826925dc56937334163656f24dd10f112c15bc7559de1 SHA256 Malware sample

Notes

For other reasons, Oracle stock is down 8.53% on the day.

Update:

Unit42 has released some IOCs for the Oracle Peoplesoft CVE-2026-35273

https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2026-06-11-Bling-Libra-targeting-Oracle-PeopleSoft-Servers.txt

Indicators of Compromise:

IPs:

45.135.232[.]140

91.215.85[.]101

108.174.202[.]99

142.11.200[.]186

142.11.200[.]187

142.11.200[.]188

142.11.200[.]189

142.11.200[.]190

176.120.22[.]24

207.89.18[.]29

Domains:

azurenetfiles[.]net

bmwebhost[.]com

onlinepaymentterminal[.]com

paymentprocessterminal[.]com

techvertix[.]com

Data Leak Site

URL**:** shnyhntww34phqoa6dcgnvps2yu7dlwzmy5lkvejwjdo6z7bmgshzayd[.]onion

SSH Key:

78166e8cd026f6f7fc612244e587c2565487f2635fc3d704987972ede619aef9

SHA256 Hashes:

9098906159e0e4c845eb918886fadc2723f2a321281b8003e471f09140321f91

c7e9332731b06644fc73e0046a2a89eaa59b09f54250e9bd622467187351711f

d65f14e5652a4330354826925dc56937334163656f24dd10f112c15bc7559de1

1 Like