A critical pre-authentication RCE chain (CVE-2026-35273, CVSS 9.8) in Oracle PeopleSoft PeopleTools 8.61 and 8.62 exploits the PSIGW Integration Broker gateway via SSRF to reach the internal PSEMHUB management servlet, then achieves code execution through Java XMLDecoder deserialization on web-tier restart. The chain is notably stealthy: execution occurs inside the WebLogic JVM with no child process spawned and no outbound beacon, making conventional behavioral and network detection ineffective. Oracle issued an out-of-band patch on June 10, 2026, but exploitation was observed in the wild from May 27 by threat actor SHADOW-AETHER-015 (ShinyHunters) targeting over 100 organizations. Post-exploitation options include JSP web shell deployment and NetNTLM credential coercion via SMB. Defenders are advised to patch immediately, restrict PSIGW network exposure, monitor envmetadata/ filesystem paths, and treat web-tier restarts as security-relevant events.