Oracle’s July 2026 Critical Patch Update — one of the largest the company has ever shipped — finally delivers the permanent fix for CVE-2026-35273, the PeopleSoft remote-code-execution flaw that the ShinyHunters extortion group exploited as a zero-day to breach more than 300 PeopleSoft servers across 100-plus organizations. The patch closes a hole that Oracle had, until now, addressed only with out-of-band mitigations issued after the attacks were already underway. It lands the same week that Nissan became one of the most prominent names to confirm employee data was stolen through it.

This is the closing chapter of a campaign we first covered in June, when the flaw was tearing through universities. The patch ends the exposure window — but for the organizations already hit, the cleanup is just beginning.

The vulnerability and the campaign

CVE-2026-35273 is a critical remote-code-execution vulnerability in Oracle PeopleSoft that ShinyHunters weaponized before any fix existed. Between May 27 and June 9, 2026, the group used it to compromise PeopleSoft instances at scale, chaining the initial foothold with a privilege-escalation flaw in PeopleTools that was serious enough to earn its own emergency Security Alert from Oracle on June 10.

The victim count is staggering: ShinyHunters told BleepingComputer it hit over 300 instances across 100 organizations, and Mandiant said it independently notified more than 100 affected orgs. The campaign fell heaviest on the education sector, but it reached far beyond it. Prior confirmed victims we’ve tracked include the University of Nottingham and the Council of Europe.

Nissan joins the list

Nissan has now disclosed that the same PeopleSoft zero-day exposed sensitive data for current and former employees across the US, Canada, Mexico, and Brazil. The compromised data is about as sensitive as HR records get:

  • Social Security and national identification numbers
  • Banking details
  • Tax records
  • Contact information and dependent/beneficiary data

Nissan has not published a headcount for those affected. In response, the automaker restricted payroll access to on-network or secured-VPN systems, added identity verification for payroll change requests, and offered impacted staff free credit and dark-web monitoring. Nissan’s disclosure sits alongside a July 3 cluster of PeopleSoft breach notifications that also named Kubota North America and Aflac’s Japan subsidiary — evidence that the fallout continues to surface weeks after the intrusions themselves.

Why the patch matters — and why it isn’t the end

Oracle’s out-of-band advisory in June gave defenders mitigations, but the definitive fix arriving only now in the July CPU means many organizations ran exposed for weeks after the campaign was already public. The lesson is uncomfortable but familiar: a mitigation is not a patch, and a patch does nothing for data that already walked out the door.

For defenders, the priorities are clear:

  • Apply the July CPU immediately. CVE-2026-35273 is confirmed exploited at scale; unpatched PeopleSoft instances remain live targets for copycats now that the details are public.
  • Assume compromise if you ran exposed. Any internet-reachable PeopleSoft instance online between late May and now should be treated as potentially breached — hunt for the ShinyHunters TTPs, not just the CVE.
  • Rotate everything the app could touch. Service credentials, database secrets, and integration tokens accessible from PeopleSoft should be considered burned.
  • Watch for extortion follow-through. ShinyHunters’ model is steal-then-pressure; victims should expect direct extortion contact and plan communications accordingly.

ShinyHunters has spent 2026 turning enterprise software supply chains — Salesforce, Oracle EBS, and now PeopleSoft — into a conveyor belt of mass breaches. Oracle has now shut this particular door. The group has shown, repeatedly, that it will simply find the next one.

Sources