MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-26 · via The Hacker News

Oracle PeopleSoft flaw exploited at scale as attackers evade WAFs

Image via The Hacker News
Image via The Hacker News

Google has warned of renewed widespread exploitation of a critical Oracle PeopleSoft vulnerability, CVE-2026-35273, which can allow unauthenticated remote code execution. The campaign has been tied to ShinyHunters and targets organizations across multiple sectors. Attackers are bypassing web application firewalls to deploy web shells.

Expanded Detail

Google has raised an alert about a new surge in attacks against a serious Oracle PeopleSoft bug, identified as CVE-2026-35273. The flaw is rated critical and could let an attacker run code remotely without first logging in.

The activity has been attributed to ShinyHunters, according to the warning, and appears aimed at many kinds of organizations. The attackers are said to sidestep web application firewalls and place web shells on compromised systems.

Context

The renewed exploitation may put organizations using Oracle PeopleSoft at risk, particularly those relying on web-facing systems for critical operations. If attackers can evade defenses and install persistent access, affected entities could face unauthorized access, service disruption, or costly remediation. The broader public may feel indirect effects through breached services or exposed personal information, though the scale and severity remain uncertain.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at The Hacker News →
Related stories
WordPress Core Vulnerability Allows Remote Code Execution Under Specific Conditions · Cybersecurity
Roundcube Webmail SQL Injection Bug Exploited Before Patch · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells.” Browse more stories.