Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw
A critical Oracle PeopleSoft vulnerability is being actively exploited to deploy web shells. The attacks bypass traditional WAF protections, highlighting gaps in perimeter-only defenses.
TL;DR
- CVE-2026-35273 is a critical Oracle PeopleSoft flaw allowing unauthenticated remote code execution
- Attackers are bypassing WAFs to exploit this vulnerability at scale
- The campaign has been linked to the ShinyHunters threat group
- Organizations should prioritize patching and implement defense-in-depth strategies
- Web shell deployment enables persistent access and lateral movement
Security researchers are warning of widespread exploitation of a critical vulnerability in Oracle PeopleSoft deployments. The flaw, tracked as CVE-2026-35273, allows attackers to execute arbitrary code without authentication, making it particularly dangerous for organizations running unpatched systems.
What makes this campaign especially concerning is the attackers' ability to bypass traditional web application firewall (WAF) protections. This technique demonstrates how perimeter-based security controls alone are insufficient against determined adversaries, requiring deeper defensive measures and proactive vulnerability management.
Vulnerability Details
- CVE-2026-35273 carries a CVSS score of 9.8, indicating critical severity
- The vulnerability enables unauthenticated remote code execution on affected systems
- It was initially exploited as a zero-day before being publicly disclosed
- Oracle PeopleSoft is widely used enterprise software, amplifying the potential impact
Attack Techniques and Mitigation
- Attackers are deploying web shells to maintain persistent access after initial compromise
- Traditional WAF solutions are being bypassed through sophisticated evasion techniques
- The campaign has been attributed to activity linked with the ShinyHunters threat group
- Organizations should immediately patch affected Oracle PeopleSoft instances
- Implement defense-in-depth strategies including network segmentation and behavioral monitoring
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.