Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Cybersecurity · September 27, 2026

Cybersecurity·thehackernews.com

Google says the ShinyHunters extortion group is behind a renewed wave of attacks against Oracle PeopleSoft servers, using a URL-encoding trick to slip past web application firewalls that were supposed to block the flaw. The bug, tracked as CVE-2026-35273 and rated 9.8 out of 10, allows unauthenticated remote code execution and is being used to plant web shells across organizations worldwide. It was originally exploited as a zero-day before patches became available, and the WAF bypass is letting attackers resume exploitation on systems assumed to be protected.

// source: thehackernews.com ↗

← Back to Blog