SimpleHelp has released patches for CVE-2026-48558, an authentication bypass vulnerability affecting deployments configured to use OpenID Connect (OIDC) authentication. The issue stems from how SimpleHelp validates identity provider assertions, Oracle has disclosed CVE-2026-35273, a critical unauthenticated remote code execution vulnerability affecting Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62. The flaw exists within the Updates Environment Management component and can be exploited remotely over HTTP without valid credentials. Successful exploitation may allow attackers to execute arbitrary code, take control of affected servers, access sensitive enterprise data, modify application logic, and disrupt critical business operations. Public reporting and threat intelligence indicate the vulnerability has already been exploited in the wild as a zero-day by the ShinyHunters threat group prior to Oracle’s advisory.
CVE-2026-35273 affects the Updates Environment Management component of Oracle PeopleSoft Enterprise PeopleTools.
Key characteristics include:
According to Oracle and threat intelligence reporting, exploitation allows attackers to gain control of vulnerable PeopleSoft environments, potentially exposing HR, payroll, financial, student, and operational data. The vulnerability requires only network access to a reachable PeopleSoft endpoint.
A NodeZero Rapid Response test has been developed to safely validate whether this remote code execution vulnerability can be exploited in your environment. The test executes real attack techniques without causing damage, giving teams immediate clarity on exposure.
| Indicator | Type | Description |
| 142.11.200[.]186-190 | IP Address | Known attacker infrastructure associated with observed exploitation activity |
| 108.174.202[.]99 | IP Address | Known attacker infrastructure associated with observed exploitation activity |
| 176.120.22[.]24 | IP Address | Known attacker infrastructure associated with observed exploitation activity |
| UNC6240 (ShinyHunters) | Threat Actor | Group attributed to active exploitation campaign |
| May 27 – June 9, 2026 | Activity Window | Period during which exploitation activity was observed |
Threat intelligence from Google Cloud and Mandiant identified active compromise and extortion campaigns targeting Oracle PeopleSoft environments. Researchers observed exploitation activity prior to Oracle’s June 10, 2026 disclosure, confirming zero-day exploitation in the wild. ShinyHunters reportedly targeted approximately 300 PeopleSoft instances across more than 100 organizations. A publicly acknowledged victim was the University of Nottingham.
Affected:
Patch:
The NodeZero® platform empowers your organization to reduce your security risks by autonomously finding exploitable weaknesses in your network, giving you detailed guidance around how to priortize and fix them, and having you immediately verify that your fixes are effective.