ShinyHunters Uses WAF Bypass Trick to Exploit Oracle PeopleSoft CVE-2026-35273

Executive Summary

The extortion gang ShinyHunters has resumed widespread exploitation of the Oracle PeopleSoft CVE‑2026‑35273 vulnerability by using a URL‑encoding trick that bypasses web application firewall (WAF) rules. The technique allows attackers to access vulnerable servers and continue delivering malicious payloads.


Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-09-26T19:03:34+00:00 - Category: threat-intel

Original Description: The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers. [...]

"Every day may not be good, but there's something good in every day."

— Unknown
Source: Bleeping Computer