Oracle PeopleSoft flaw exploited at scale as attackers evade WAFs

Google has warned of renewed widespread exploitation of a critical Oracle PeopleSoft vulnerability, CVE-2026-35273, which can allow unauthenticated remote code execution. The campaign has been tied to ShinyHunters and targets organizations across multiple sectors. Attackers are bypassing web application firewalls to deploy web shells.
Google has raised an alert about a new surge in attacks against a serious Oracle PeopleSoft bug, identified as CVE-2026-35273. The flaw is rated critical and could let an attacker run code remotely without first logging in.
The activity has been attributed to ShinyHunters, according to the warning, and appears aimed at many kinds of organizations. The attackers are said to sidestep web application firewalls and place web shells on compromised systems.
The renewed exploitation may put organizations using Oracle PeopleSoft at risk, particularly those relying on web-facing systems for critical operations. If attackers can evade defenses and install persistent access, affected entities could face unauthorized access, service disruption, or costly remediation. The broader public may feel indirect effects through breached services or exposed personal information, though the scale and severity remain uncertain.