Cyberattack targets education sector via Oracle PeopleSoft vulnerability
The ShinyHunters group (UNC6240) launched a large-scale attack, exploiting a critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft software. The incident occurred before the developer's official advisory. The threat actors compromised over 100 organizations, 68% of which are universities and colleges, primarily in the US.
Technical details and risks for ERP systems
The CVE-2026-35273 vulnerability (CVSS score of 9.8) allows unauthenticated remote code execution (RCE) without user interaction. Educational institutions are attractive targets due to large volumes of personal and research data, decentralized IT infrastructure, limited security budgets, and open networks. The use of legacy monolithic ERP systems complicates prompt patching.
Market implications
This attack demonstrates that relying on legacy, monolithic ERP systems creates severe security bottlenecks, as they are difficult to patch quickly during active zero-day exploits. For the education sector and broader industries, this exposure risks the theft of massive volumes of sensitive personal and research data, potentially leading to operational disruption and long-term regulatory and financial consequences.
Where to start
To improve resilience, experts recommend decomposing monolithic ERP systems. Gradually migrating functions to a microservices architecture using API Gateways, IAM systems, or low-code platforms (such as UnityBase) helps isolate risks and accelerate updates.
CISA recommends implementing Cybersecurity Performance Goals (CPGs):
- regular vulnerability scanning and remediation;
- multi-factor authentication (MFA) and the principle of least privilege;
- data encryption and backups;
- using SIEM systems for anomaly monitoring;
- testing incident response plans.
Prepared by a Software Ukraine member. Original publication.