Oracle's Biggest Patch Day Ever: 1,449 Fixes as ShinyHunters' Zero-Day Chain Hits 100+ Organizations
Oracle released its largest-ever quarterly patch update on July 21: 1,449 security fixes including ten vulnerabilities scored a perfect CVSS 10.0 — and the most critical PeopleSoft zero-day chain had already been weaponized by the ShinyHunters group to breach over 100 organizations.
Three Key Takeaways
Two CVSS 9.8 zero-days were chained together. CVE-2026-35278 is a pre-authentication remote code execution flaw in PeopleSoft PeopleTools' Environment Management Hub — attackers can execute arbitrary code via HTTP requests without any credentials. ShinyHunters paired it with a privilege escalation flaw (CVE-2026-35273) to compromise over 300 PeopleSoft instances across 100-plus organizations between May 27 and June 9.
Education sector bore the brunt. Universities and higher education institutions were the primary victims. ShinyHunters operates on a data theft and extortion model: steal records, post samples with a ransom deadline, publish everything when the deadline passes. The group has previously targeted Microsoft, AT&T, and Ticketmaster.
1,449 patches set an Oracle record. Beyond PeopleSoft, the July Critical Patch Update covers WebLogic, Identity Manager, WebCenter, and other core products, with ten CVSS 10.0 vulnerabilities spread across multiple product lines. Oracle urged all customers to deploy patches immediately, as at least one vulnerability was actively exploited in the wild.
WangDou's Take
PeopleSoft might sound like ancient history to most people — it's enterprise HR and finance software Oracle bought for $10.3 billion back in 2005, and it still runs as the backbone of countless American universities and government agencies. Here's the kicker: a system designed 20 years ago had a management hub that accepted HTTP requests with zero authentication. ShinyHunters started attacking on May 27; Oracle didn't ship the patch until July 21 — that's nearly two months of open season on any unprotected PeopleSoft instance. The number 1,449 patches sounds scary, but what's scarier is the institutions that still haven't applied them. University IT departments go on summer break. Hackers don't.
Source: TechTimes, The Hacker News, ByteIota
