• Login
teqpost
  • Home
  • Hardware
  • Gaming
  • Gadgets
  • AI
  • Software
  • Security
  • Policy
No Result
View All Result
teqpost
  • Home
  • Hardware
  • Gaming
  • Gadgets
  • AI
  • Software
  • Security
  • Policy
No Result
View All Result
teqpost
No Result
View All Result

Home / Security / ShinyHunters bypass WAFs to exploit Oracle PeopleSoft flaw

ShinyHunters bypass WAFs to exploit Oracle PeopleSoft flaw

byLotfi Ben Taleb
September 27, 2026
in Security
Reading Time: 3 mins read
Rows of blue-lit server hard drive caddies in a data center rack
Share on Facebook
Share on Twitter

Google is warning of renewed mass exploitation of a critical Oracle PeopleSoft vulnerability, tracked as CVE-2026-35273, in a campaign that targets multiple sectors worldwide and has been linked to the ShinyHunters extortion group.

The flaw carries a CVSS score of 9.8 and allows unauthenticated remote code execution against PeopleSoft servers, meaning an attacker needs no valid credentials to run commands on a vulnerable system. It was first exploited as a zero-day before defenders had a signature to catch it, and the current wave is a second run at the same weakness, now that patches and web application firewall rules exist for anyone who applied them.

How the WAF bypass works

BleepingComputer reports that the attackers are using a URL-encoding trick to slip past the web application firewall rules written to catch the original exploitation pattern. Encoding the malicious request differently is enough to dodge a filter built around one specific string, which is why a WAF rule is a mitigation and never a substitute for patching. Once past the filter, the attackers deploy web shells on the compromised server, giving them a persistent foothold for further access or extortion.

Who is behind the attacks

The attribution sits at two different levels of certainty depending on the source. Google describes the campaign as ShinyHunters-linked, a hedge that stops short of naming the group outright. BleepingComputer names the operators directly as the ShinyHunters extortion gang. The gap between the two is normal for fast-moving campaigns, where technical indicators arrive before attribution is confirmed, but it is worth reading past the headline: “linked to” and “run by” are not the same claim.

Either way, the objective fits the group’s usual playbook: gain unauthenticated access, drop a web shell for persistence, and pull data out to use as leverage rather than encrypting it in place. That makes patching the priority regardless of which description of the attackers turns out to be accurate.

Why the Oracle PeopleSoft vulnerability keeps resurfacing

The Oracle PeopleSoft vulnerability follows a familiar pattern for enterprise resource planning software: it is internet-facing, holds payroll and HR records outright, and gets patched slowly because taking it offline disrupts finance and HR operations. The same pattern played out with the WSO2 and Adobe Commerce flaws that made CISA’s exploited vulnerabilities list earlier this year: a critical bug exploited quietly as a zero-day, followed by a louder, broader wave once the technique for reaching it became public.

CVE-2026-35273 has not yet appeared on that CISA list. A WAF bypass that revives mass exploitation of a 9.8-rated flaw is exactly the kind of activity that tends to get a vulnerability added, and it is worth checking the NVD entry for CVE-2026-35273 for updates to its status.

What PeopleSoft administrators should do now

The WAF bypass means firewall rules alone no longer stop this exploit chain. Administrators running PeopleSoft should confirm the underlying patch is applied rather than relying on the WAF rule that mitigated the original zero-day, and should check logs and file systems for web shells already dropped during the first wave of exploitation, since a bypass that revives an old flaw often finds servers that were never fully remediated the first time.

What to watch: whether CVE-2026-35273 is added to CISA’s Known Exploited Vulnerabilities catalogue, and whether Oracle issues further guidance now that the existing WAF mitigation has been bypassed.

Tags: vulnerability
Previous Post

PNY denies RTX 5090 warranty claim over melted cable

Next Post

GPT-6 Astra cracks an 85-year-old Enigma message in two days

Related Posts

Tangled colored network patch cables running into a server rack panel
Security

Citrix confirms two NetScaler zero-days under active attack

September 28, 2026
Rendered illustration of a data center corridor lined with server racks showing blue status lights
Security

WSO2 and Adobe Commerce flaws land on CISA’s exploited list

September 26, 2026
ASUS ProArt monitor with black screen off, on a stand, against a white wall
Security

Asus warns customers of eShop data breach

September 24, 2026
0 0 votes
Article Rating
Subscribe
Notify of
0 Comments

Popular News

Three Samsung phone backs side by side, green with many cameras, purple and cream with three cameras

Galaxy S27 renders show a design split from the Ultra

September 28, 2026
A Radeon graphics card installed in a PC case, lit by green and blue ambient light

Modders get DLSS 5 running on AMD’s RDNA 4 GPUs

September 7, 2026
Close-up of an iPhone's glass back and dual rear camera lenses lit from above

iPhone Duo 3D model lets you open the hinge before launch

September 20, 2026
Close-up of a GeForce RTX graphics card installed in a PC case with a blurred power cable bundle

DLSS 5 mods expose RTX 5090’s power connector limit

September 27, 2026
Next Post
Close-up of a mechanical device's internal gears, wiring, and rotor-like metal plates

GPT-6 Astra cracks an 85-year-old Enigma message in two days

Technology for enthusiasts and gamers. Hardware, gaming and the software in between, with the spec sheets read properly and the marketing taken back out.

Categories

Categories

  • AI
  • Gadgets
  • Gaming
  • Hardware
  • Policy
  • Security
  • Software
Site Links
  • Latest
  • About
  • Contact
About
  • How We Work
  • Privacy Policy

© 2026 teqpost. All rights reserved.

  • Privacy Policy
  • Contact

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Hardware
  • Gaming
  • Gadgets
  • AI
  • Software
  • Security
  • Policy

© 2026 JNews - Premium WordPress news & magazine theme by Jegtheme.

wpDiscuz
0
0
Would love your thoughts, please comment.x
()
x
| Reply