
“Assuming it is real, this would mean PeopleSoft has a second critical, unpatched preauth RCE in the same window as CVE-2026-35273, a pattern of recurring critical exposure rather than one isolated bug,” he said. “ShinyHunters’ own claim that they are already using it against other, unnamed Fortune 500 targets would mean every PeopleSoft customer is currently exposed to an unpatchable, undisclosed flaw with no vendor guidance to act on, a meaningfully worse position than the WAF-bypass story, since there is no mitigation to attempt while waiting on Oracle to confirm something it has not acknowledged.”
Jeff Valdes, a director at consulting firm Acceligence, added that Oracle’s silence is unwarranted.
“I think customers reasonably want more communication from the vendor,” he said. “They want to understand whether Oracle’s original guidance remains sufficient, whether there are additional mitigations customers should implement, whether Oracle is seeing anything through its own support organization that changes the risk picture, and whether there are configurations or architectural choices that materially increase exposure. Those are operational security questions that can be addressed without discussing attribution, arrests, investigative techniques or anything else that might interfere with an FBI investigation.”
