Attackers Bypass WAFs to Exploit Oracle PeopleSoft CVE-2026-35273 and Deploy Web Shells
Executive Summary
Google warns of a renewed mass exploitation campaign targeting multiple sectors worldwide. Attackers are bypassing web application firewalls to exploit the critical Oracle PeopleSoft vulnerability CVE‑2026‑35273 (CVSS 9.8), enabling unauthenticated remote code execution. The ShinyHunters-linked activity deploys web shells, and the flaw was first used as a zero‑day exploit.
Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-26T11:46:40+00:00 - Category: threat-intel
Original Description: Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution. The vulnerability was first exploited as a zero-day
"There are two primary choices in life: to accept conditions as they exist, or accept responsibility for changing them."
— Denis Waitley