ShinyHunters Exploits URL-Encoding Trick to Bypass WAF in Oracle PeopleSoft Attacks
Extortion gang leverages encoding bypass to resume exploitation of CVE-2026-35273 on vulnerable servers

Key Takeaways
- ShinyHunters is using a URL-encoding trick to bypass WAF rules mitigating CVE-2026-35273 in Oracle PeopleSoft.
- The bypass allows resumed widespread exploitation of the vulnerability on vulnerable servers.
- Oracle PeopleSoft users should apply security patches and update WAF rules to detect encoding bypass patterns.
- The exact scope of exploitation and data compromised are unconfirmed and under investigation.
Quick answers
- What happened?
- The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of the vulnerability on vulnerable servers, according to BleepingComputer reporting.
- Which products are affected?
- Oracle PeopleSoft
- What should defenders do?
- Apply Oracle PeopleSoft security patches for CVE-2026-35273. Update WAF rules to detect and block URL-encoding bypass patterns associated with the CVE-2026-35273 exploitation attempts. Monitor Oracle security advisories for further guidance.
- Which vulnerabilities are involved?
- CVE-2026-35273
The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers. According to BleepingComputer, the attack campaign leverages encoding techniques to circumvent WAF mitigations, enabling actors to target vulnerable Oracle PeopleSoft installations globally. The exploitation of CVE-2026-35273 had been previously mitigated through WAF rule updates, but the new bypass technique allows ShinyHunters to reinstate attacks. Oracle PeopleSoft users are advised to apply the latest security patches and update WAF rules to detect URL-encoding bypass patterns. The full extent of exploited servers and any data compromised remain under investigation.
Security Details
ShinyHunters is leveraging a URL-encoding technique to bypass Web Application Firewall rules that were previously mitigating the Oracle PeopleSoft CVE-2026-35273 flaw. This bypass allows the threat actors to resume widespread exploitation of the vulnerability on vulnerable servers. The exploitation had been previously checked through WAF rule updates, but the new encoding technique circumvents those defenses.
Affected products
Oracle PeopleSoft
Mitigation
Apply Oracle PeopleSoft security patches for CVE-2026-35273. Update WAF rules to detect and block URL-encoding bypass patterns associated with the CVE-2026-35273 exploitation attempts. Monitor Oracle security advisories for further guidance.
Sources
BleepingComputer
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
Sep 26, 2026 · 19:03
Original link
Related Security News

Former US Air Force Members Sentenced to Prison for Business Email Compromise Scams
Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. The sentencing, reported by BleepingComputer in September 2026, concluded a federal case targeting individuals who abused their military backgrounds to conduct financially motivated email fraud. The attacks spanned multiple years prior to sentencing, though specific victim counts and total financial losses were not detailed in the reporting. The case underscores the legal consequences of using military credentials and training for cyber-enabled fraud.




