Technology

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

The Hacker News September 26, 2026 4 views
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Advertisement

Google has issued a warning about a renewed wave of mass exploitation targeting Oracle PeopleSoft, a widely used enterprise software platform. The campaign, linked to the ShinyHunters threat group, focuses on a critical flaw identified as CVE-2026-35273.

The vulnerability, which carries a CVSS score of 9.8, permits unauthenticated remote code execution. Attackers can leverage this weakness to gain full control over affected systems without needing valid credentials.

Although the flaw was initially discovered as a zero‑day, it has since become a known issue that is now being weaponised on a large scale. Google’s alert highlights that the exploitation is occurring across multiple sectors worldwide.

Oracle has not yet released a patch for CVE-2026-35273, and users of PeopleSoft are urged to monitor updates closely and apply any available fixes as soon as they become available.

Security experts advise organisations to review their network perimeter defenses, including Web Application Firewalls, to detect and block attempts to exploit this vulnerability. Maintaining up‑to‑date software and monitoring for suspicious activity remain key mitigations against the ongoing threat.

<small>Source: The Hacker News — read the original story there.</small>

How did this make you feel?

Never miss a story

Get the best of SpeakOX in your inbox. No spam, unsubscribe anytime.

Advertisement

Category
Technology

Advertisement