Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
26 September 2026
Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally.
The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution.
The vulnerability was first exploited as a zero-day