HackerFeeds

CyberSecurity News

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

The Hacker News
· September 26, 2026

AI summary

Google is warning about a renewed campaign exploiting a known Oracle PeopleSoft vulnerability, targeting multiple sectors globally. The vulnerability, with a CVSS score of 9.8, allows for unauthenticated remote code execution. This flaw is being used by attackers linked to ShinyHunters, who are bypassing web application firewalls to deploy web shells. The vulnerability was initially exploited as a zero-day issue. Attackers are now actively exploiting it in a mass campaign. The vulnerability is identified as CVE-2026-35273.

Vulnerabilities mentioned

Read the full article at The Hacker Newsthehackernews.com/2026/09/attackers-bypass-wafs-to-exploit-oracle.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.