Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
Google has issued a warning regarding renewed mass exploitation of a critical vulnerability in Oracle PeopleSoft. The campaign, linked to threat actors associated with ShinyHunters, involves the weaponization of CVE-2026-35273, a flaw that could allow unauthenticated remote code execution. Attackers are reported to be bypassing Web Application Firewalls (WAFs) to deploy web shells and gain unauthorized access to PeopleSoft environments across multiple sectors worldwide. The vulnerability was initially exploited as a zero-day, and exploitation activity has been renewed in September 2026.

