Hackers Just Found a Way Around Oracle PeopleSoft's Defenses
Robert Moore ·
Listen to this article~3 min
Google warns of mass exploitation of a critical Oracle PeopleSoft flaw (CVE-2026-35273) by ShinyHunters. Attackers bypass WAFs to deploy web shells. Learn how to protect your systems.
### A Critical Flaw Is Being Exploited Right Now
Google's security team is raising alarms about a fresh wave of attacks targeting Oracle PeopleSoft. This isn't some minor bug—it's a critical vulnerability that hackers are actively using to break into systems worldwide. The campaign is linked to ShinyHunters, a group known for aggressive exploitation tactics.
The flaw, tracked as CVE-2026-35273, carries a CVSS score of 9.8 out of 10. That's about as bad as it gets. It allows unauthenticated remote code execution, which is a fancy way of saying an attacker can run their own code on your server without needing a password. And they're doing it by bypassing Web Application Firewalls (WAFs) that were supposed to block such attacks.
### Why WAFs Aren't Stopping This
You'd think a WAF would catch this. But attackers have gotten smarter. They're finding ways to slip past these defenses, often by encoding malicious requests or exploiting gaps in how WAFs inspect traffic. Once inside, they deploy web shells—small scripts that give them persistent access to your system.
> "The vulnerability was first exploited as a zero-day, meaning the bad guys knew about it before Oracle could patch it. That's a nightmare scenario for any organization."
### What This Means for You
If you're running Oracle PeopleSoft, you need to act fast. Here's what you should do:
- **Apply the latest patches immediately.** Oracle has released fixes, but many systems remain unpatched.
- **Check for signs of compromise.** Look for unusual files, unexpected outbound traffic, or strange admin accounts.
- **Don't rely solely on your WAF.** Layer your defenses with intrusion detection, regular scans, and strict access controls.
- **Monitor for web shells.** These often have telltale names or patterns—keep an eye out.
### The Bigger Picture
This isn't just about one vulnerability. It's a reminder that attackers are constantly evolving. They're targeting multiple sectors globally, from finance to healthcare. The ShinyHunters group has a history of going after high-value data, and they're not slowing down.
For security teams, the lesson is clear: assume you're a target. Keep your systems updated, stay vigilant, and don't underestimate the creativity of attackers. A WAF is just one piece of the puzzle—it's not a silver bullet.
And if you're using antidetect browsers or other privacy tools, remember that the same techniques that protect your identity can also be abused by bad actors. Stay informed, stay safe, and always verify before you trust.