Lead Analysis
Security & Risk6 min

Oracle Releases Record CPU with 1,449 Patches and Closes Door Exploited by ShinyHunters on 300 PeopleSoft Servers

Sala de operações de segurança de madrugada com analista solitário e alerta vermelho na tela central.

Oracle published the largest Critical Patch Update in its history on Tuesday, with 1,449 patches and 1,235 unique CVEs. Among them is CVE-2026-35278 for PeopleSoft, used by ShinyHunters to compromise more than 100 organizations.

Oracle released its July Critical Patch Update on Tuesday, with 1,449 patches covering 1,235 unique CVEs across 32 product families. This is the largest quarterly CPU ever announced by the company and includes an item that alters the risk calculation for any client still operating PeopleSoft: CVE-2026-35278, a pre-authenticated RCE in PeopleTools with a CVSS of 9.8, is the same flaw that the ShinyHunters group exploited to compromise over 300 servers in more than 100 organizations between May 27 and June 9.


The PeopleSoft case warrants further unpacking. ShinyHunters linked CVE-2026-35278 with CVE-2026-35273, a privilege escalation vulnerability that Oracle had previously addressed in a Security Alert outside the normal release cycle on June 10. The combination allows remote code execution as a root user on the application server. Among the confirmed victims, the Moody Bible Institute exposed 2.3 million personal records, and the NAIC, a U.S. insurance regulator association, stated in a release that public data was exfiltrated. Universities, seminaries, and state agencies in the U.S. and the UK dominated the list, according to reports from Arctic Wolf and Google Cloud's Mandiant unit.


What Makes This CPU Structurally Different


Beyond PeopleSoft, the technical headline is a CVE with a CVSS of 9.9 in the Oracle Database Server affecting all supported versions from 19.3 to 23.26.2, including Autonomous Database. There is no public evidence of active exploitation, but the installed base is the most critical within Oracle's portfolio: Ericsson, JPMorgan, LATAM, and most banks and telecoms globally use this line in production. Oracle E-Business Suite received 410 patches, accounting for 28.3% of the total, a historical peak for the product. Fusion Middleware, MySQL, and GoldenGate included hundreds of other fixes, indicating that Oracle's internal cycle has accelerated the cadence of disclosure.


Of the total patches, 18% were classified as critical and 52.7% as high severity, according to Tenable, raising the proportion above the average of the last eight CPUs. Ben Smith, Chief Engineer at Tenable, stated in a release that "the highest-risk defects continue to concentrate in legacy products that customers should have decommissioned two cycles ago but did not due to high migration costs."


For Those Operating PeopleSoft in a Critical Environment


The ShinyHunters exploitation window lasted 14 days before the first public alert from Arctic Wolf, and another 28 days before the official CPU. If the timeline repeats in the next cycle, companies that fail to apply patches in an aggressive window will remain on the radar. In the U.S., the Department of Education now requires institutions funded by Federal Student Aid to apply critical RCE patches within 72 hours of CPU publication, a deadline formalized in a memo from August 2025. In Germany, the BSI classifies unauthenticated RCE in ERP as "warnstufe rot" and mandates notification to the competent authority within 24 hours. In France, the ANSSI maintains a 5-business-day deadline for OIVs, and the Japanese agency NISC updated its vulnerability management guide in June to require patch testing in pre-production within a 48-hour window when the vendor confirms active exploitation.


An interesting point of consideration lies in the overlap with the outsourcing sector. TCS, Infosys, and Wipro operate PeopleSoft for a large share of the American healthcare sector and for public universities in the UK and Australia. A typical managed services contract gives the integrator a 30-day window to apply critical patches, which directly conflicts with the new requirement from the Department of Education. If a U.S. client enforces a 72-hour SLA, the cost of compliance falls on the Indian service provider, not on the CIO.


What Is Not Included in This CPU


Oracle did not provide a timeline for a version that rewrites the HTTP subsystem of PeopleTools where CVE-2026-35278 originates, only a mitigation via patch. It also did not confirm whether Autonomous Database instances have been updated against the CVE 9.9 from Database Server, leaving self-managed clients exposed through a window that Oracle historically applies in 7 to 14 days. There is no public mention that ShinyHunters began exploiting the PeopleSoft chain before Oracle issued formal advisory, a discussion on "responsible disclosure" that Mandiant raised in its June report, to which Oracle has not responded through official channels.

Lead Analysis