CVE-2026-35273 was exploited as a zero-day before a fix existed
Assessment
GTIG documents exploitation of CVE-2026-35273 beginning May 27, 2026 and running to June 9, 2026 — largely against the education sector — before Oracle issued its Security Alert for the flaw on June 10, 2026. That sequence makes the initial wave genuine zero-day activity: the attackers were exploiting the PSEMHUB deserialization bug weeks before a patch or public advisory existed, not merely racing defenders after disclosure. The distinction matters because the widely-covered September 2026 mass-exploitation wave is an n-day campaign against unpatched systems, which can leave the impression that exploitation only started after the fix. It did not: the bug was a zero-day first, and the September activity is the second, larger act.
Where this claim appeared
Google Threat Intelligence Group (Mandiant) · 2026-09-26
https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoftWhat “Verified” means
Established by primary sources — the original disclosure, a vendor incident report, a court filing, a government advisory, or the affected party itself. Where a claim is material, at least two independent sources agree.
5 of 5 · rating scale
Assessed in
ShinyHunters (UNC6240) bypass a WAF with one URL-encoded character to mass-exploit PeopleSoft CVE-2026-35273Think this assessment is wrong? Report an error.