Oracle released an emergency out-of-band patch for CVE-2026-35273, a critical CVSS 9.8 unauthenticated SSRF-to-RCE vulnerability in PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62. Mandiant confirmed active zero-day exploitation by ShinyHunters (UNC6240) between May 27 and June 9, 2026, targeting over 100 organizations — 68% in higher education. The exploit chain targets PSEMHUB and PSIGW endpoints, can trigger outbound SMB connections to capture NetNTLM hashes, and post-exploitation involved deploying MeshCentral agents disguised as Azure services for C2. Organizations should patch immediately, disable or restrict the EMHub service, block external access to vulnerable endpoints, and investigate for compromise using the provided IOCs including file hashes, C2 IPs, and host-based indicators.