Google is warning of renewed mass exploitation of a critical Oracle PeopleSoft vulnerability, tracked as CVE-2026-35273, in a campaign that targets multiple sectors worldwide and has been linked to the ShinyHunters extortion group.
The flaw carries a CVSS score of 9.8 and allows unauthenticated remote code execution against PeopleSoft servers, meaning an attacker needs no valid credentials to run commands on a vulnerable system. It was first exploited as a zero-day before defenders had a signature to catch it, and the current wave is a second run at the same weakness, now that patches and web application firewall rules exist for anyone who applied them.
How the WAF bypass works
BleepingComputer reports that the attackers are using a URL-encoding trick to slip past the web application firewall rules written to catch the original exploitation pattern. Encoding the malicious request differently is enough to dodge a filter built around one specific string, which is why a WAF rule is a mitigation and never a substitute for patching. Once past the filter, the attackers deploy web shells on the compromised server, giving them a persistent foothold for further access or extortion.
Who is behind the attacks
The attribution sits at two different levels of certainty depending on the source. Google describes the campaign as ShinyHunters-linked, a hedge that stops short of naming the group outright. BleepingComputer names the operators directly as the ShinyHunters extortion gang. The gap between the two is normal for fast-moving campaigns, where technical indicators arrive before attribution is confirmed, but it is worth reading past the headline: “linked to” and “run by” are not the same claim.
Either way, the objective fits the group’s usual playbook: gain unauthenticated access, drop a web shell for persistence, and pull data out to use as leverage rather than encrypting it in place. That makes patching the priority regardless of which description of the attackers turns out to be accurate.
Why the Oracle PeopleSoft vulnerability keeps resurfacing
The Oracle PeopleSoft vulnerability follows a familiar pattern for enterprise resource planning software: it is internet-facing, holds payroll and HR records outright, and gets patched slowly because taking it offline disrupts finance and HR operations. The same pattern played out with the WSO2 and Adobe Commerce flaws that made CISA’s exploited vulnerabilities list earlier this year: a critical bug exploited quietly as a zero-day, followed by a louder, broader wave once the technique for reaching it became public.
CVE-2026-35273 has not yet appeared on that CISA list. A WAF bypass that revives mass exploitation of a 9.8-rated flaw is exactly the kind of activity that tends to get a vulnerability added, and it is worth checking the NVD entry for CVE-2026-35273 for updates to its status.
What PeopleSoft administrators should do now
The WAF bypass means firewall rules alone no longer stop this exploit chain. Administrators running PeopleSoft should confirm the underlying patch is applied rather than relying on the WAF rule that mitigated the original zero-day, and should check logs and file systems for web shells already dropped during the first wave of exploitation, since a bypass that revives an old flaw often finds servers that were never fully remediated the first time.
What to watch: whether CVE-2026-35273 is added to CISA’s Known Exploited Vulnerabilities catalogue, and whether Oracle issues further guidance now that the existing WAF mitigation has been bypassed.








