When Legacy Enterprise Software Becomes a Single Point of Failure
Oracle's July 2026 Critical Patch Update delivered 1,235 CVE fixes across 32 product families — one of the largest quarterly patch releases in the company's history. Buried in that avalanche of fixes was CVE-2026-35273, a 9.8-rated remote code execution vulnerability in PeopleSoft that had already been exploited as a zero-day to compromise over 100 organizations — 68% of them universities.
The attack window ran from May 27 to June 9, roughly two weeks before Oracle publicly acknowledged the flaw. During that period, the ShinyHunters extortion group used automated scanning to identify and breach vulnerable PeopleSoft deployments at scale, ultimately exposing 2.3 million personal records at Moody Bible Institute alone. The University of Nottingham confirmed that 454,600 current and former students' records were published on ShinyHunters' leak site.
What makes this breach instructive isn't the vulnerability itself — it's what it reveals about the structural fragility of enterprise IT.
Continue reading the full article on TildAlice
Top comments (0)