ThreatPaper
Verified

CVE-2026-35273 was exploited as a zero-day before a fix existed

Assessment

GTIG documents exploitation of CVE-2026-35273 beginning May 27, 2026 and running to June 9, 2026 — largely against the education sector — before Oracle issued its Security Alert for the flaw on June 10, 2026. That sequence makes the initial wave genuine zero-day activity: the attackers were exploiting the PSEMHUB deserialization bug weeks before a patch or public advisory existed, not merely racing defenders after disclosure. The distinction matters because the widely-covered September 2026 mass-exploitation wave is an n-day campaign against unpatched systems, which can leave the impression that exploitation only started after the fix. It did not: the bug was a zero-day first, and the September activity is the second, larger act.

Where this claim appeared

Google Threat Intelligence Group (Mandiant) · 2026-09-26

https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft

What “Verified” means

Established by primary sources — the original disclosure, a vendor incident report, a court filing, a government advisory, or the affected party itself. Where a claim is material, at least two independent sources agree.

5 of 5 · rating scale

Assessed in

ShinyHunters (UNC6240) bypass a WAF with one URL-encoded character to mass-exploit PeopleSoft CVE-2026-35273

Think this assessment is wrong? Report an error.