```html ```
top of page

Oracle Shipped 1,200 Patches Tuesday. ShinyHunters Had Been Inside PeopleSoft Since May.

  • Writer: Patrick Duggan
    Patrick Duggan
  • 1 hour ago
  • 4 min read

On July 21, Oracle released its quarterly Critical Patch Update. It was the largest in the company's history — north of 1,200 fixes across the product suite, five of them critical. Records are supposed to be a good thing. This one is not a flex. It is a measure of how much was left unpatched while people were already being robbed.


Because the two vulnerabilities in that pile that actually matter were not theoretical. They were being exploited in the wild for weeks — in one case, months — before Oracle shipped the fix. If you run Oracle software, the size of the dump is not the story. The lag between exploitation and patch is the story, and it is the thing that should change how you treat every Oracle product you own.



The PeopleSoft chain that hit 100+ orgs before the patch existed


The headline flaw is a PeopleSoft chain. ShinyHunters — the financially-motivated extortion crew Mandiant tracks for this campaign as UNC6240 — paired two critical-rated bugs in Oracle PeopleTools, both living in the Environment Management Hub:


[CVE-2026-35278](https://analytics.dugganusa.com/api/v1/dredd/kev-gap?cve=CVE-2026-35278) is a pre-authentication remote code execution flaw, CVSS 9.8. An attacker who can reach the Environment Management Hub HTTP endpoint executes arbitrary code on the application server. No login required.


[CVE-2026-35273](https://analytics.dugganusa.com/api/v1/dredd/kev-gap?cve=CVE-2026-35273) is a server-side request forgery flaw, also CVSS 9.8, chained with the first to complete the takeover.


Here is the timeline that matters. ShinyHunters ran this chain against the wild from May 27 through June 9, compromising more than 300 PeopleSoft servers across more than 100 organizations. Sixty-eight percent of the notified victims were universities and colleges — institutions that run PeopleSoft for student records, payroll, and financial aid, and that are chronically under-resourced on security. Oracle's fix landed in the July 21 CPU. That is a patch arriving roughly seven weeks after the campaign was already burning through the higher-education sector.


The command-and-control was a MeshCentral agent dressed up to look like Microsoft Azure — the domain azurenetfiles.net, serving its agent over a WebSocket path built to blend into normal Azure traffic. That indicator was sitting in public community feeds — URLhaus flagged the exact agent path on May 28, other community feeds picked up the bare domain in mid-June — and it is in our distributed blocklist. That is the point worth sitting with: the infrastructure this crew used to run 100+ breaches was publicly known, and blockable, for the better part of two months before the vendor whose product they were exploiting shipped a patch. A defender pulling a free feed was dropping the C2 while Oracle was still writing the fix.


We are not going to claim we discovered that C2. Community feeds did, and we say so. What we did was carry it, correlate it, and put it somewhere a cash-poor university IT shop could pull it without a purchase order. That is the job.



The EBS bug is the same movie, longer


The other one that matters is not new to our readers. CVE-2026-46817, a CVSS 9.8 unauthenticated takeover in the Oracle E-Business Suite Payments module, has been under active attack since late June. We wrote it up on July 12 as the third critical unauthenticated EBS flaw in nine months.


Then, on July 20, Estée Lauder confirmed to the Vermont Attorney General that attackers had been inside its EBS environment and walked out with employee names, Social Security numbers, and health data. The intruders got in around August 9, 2025. The disclosure came July 10, 2026. Eleven months of dwell time inside an ERP holding HR data for one of the largest cosmetics companies on earth.


Two products. Two unauthenticated 9.8s. One breached for two months before the patch, the other for eleven months before disclosure. That is not a run of bad luck. That is a pattern in how Oracle's flagship enterprise applications get attacked and how long it takes anyone — including Oracle — to catch up.



What to do tonight


PeopleSoft: Apply the July 2026 CPU now — this is the fix for the 35278 and 35273 chain. Before you finish patching, assume compromise on any internet-reachable PeopleSoft instance and hunt. Look at your Environment Management Hub exposure first; it should never be reachable from the open internet. Search for MeshCentral agents you did not install, and for outbound connections to azurenetfiles.net or WebSocket traffic masquerading as Azure. Pull our feed and block the campaign infrastructure at the DNS and IP tier.


E-Business Suite: Patch CVE-2026-46817 if you somehow still have not. Then check dwell — the Estée Lauder timeline says attackers sit in EBS for months, so a clean patch does not mean a clean house. Review the Payments and File Transmission components for unauthenticated access, and audit for data staged for exfiltration.


Everything else in the CPU: Five criticals shipped Tuesday. WebLogic, Identity Manager, and WebCenter all took critical fixes. If it is internet-facing and it is Oracle, it is on the target list. Prioritize the unauthenticated ones.



The point


A record patch count is Oracle telling on itself. It means a record amount of exploitable surface was sitting in shipping product until this week. The two flaws that were already being used to breach hundreds of organizations were patched on Oracle's schedule, not the attacker's — and the attacker's schedule started in May.


You cannot fix Oracle's cadence. You can shrink your own window: patch the two 9.8s first, hunt for the dwell the patches will not remove, and pull a free feed so the campaign infrastructure is blocked whether or not the vendor has caught up. The universities that run PeopleSoft should not have to buy a threat-intel subscription to keep ShinyHunters out. The indicators are free. Go use them.




Every indicator in this post is in the feed. Free.

1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.


Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page