Google warns of renewed mass exploitation of a critical Oracle PeopleSoft flaw. Attackers are bypassing WAFs and deploying web shells. Here's what you need to know.
Google just dropped a warning that should make anyone running Oracle PeopleSoft sit up straight. A known vulnerability is being exploited again — at scale — and attackers are finding creative ways around the security tools you probably trust to stop them.
Let me break down what's actually happening, because this one's serious.
### What Is CVE-2026-35273?
At the center of this mess is CVE-2026-35273, a critical flaw with a CVSS score of 9.8. That's about as bad as it gets on the severity scale.
In plain terms? An attacker doesn't need any login credentials to pull this off. They can run their own code on your server remotely — no username, no password, no nothing. It's the digital equivalent of someone walking into your house because the front door was never actually locked.
The vulnerability was first exploited as a zero-day, meaning the bad guys found it before Oracle could patch it. And now, according to Google's threat intelligence team, it's being weaponized again in a broad campaign hitting organizations across multiple sectors worldwide.
### Who's Behind This?
The activity has been linked to ShinyHunters, a group that's built a reputation for aggressive, financially motivated attacks. They're not hobbyists. They're organized, they move fast, and they specifically target enterprise software that companies depend on every single day.
Here's the thing that's really got security researchers worried:
- **WAF bypass techniques** — Attackers are using methods to slip past Web Application Firewalls, the very tools companies deploy specifically to block this kind of exploit
- **Web shell deployment** — Once inside, they're planting persistent backdoors that let them come and go as they please
- **Multi-sector targeting** — This isn't hitting one industry. Finance, healthcare, education, government — nobody's off the table
- **Mass exploitation** — We're not talking about a handful of victims. This is a broad, automated campaign
### Why WAF Bypasses Matter So Much
If you're thinking, "I've got a WAF, I'm covered" — that's exactly the assumption these attackers are counting on.
Web Application Firewalls are great at stopping known attack patterns. They're your first line of defense, and they catch a lot. But they're not magic. Skilled attackers study how WAFs work, find the gaps in their rules, and craft requests that look legitimate enough to pass through.
As one security researcher put it: *"A WAF is a speed bump, not a wall. If you're relying on it as your only defense, you've already lost."*
That's not fearmongering. That's just how layered security works — or doesn't work when you skip the layers.
### What Should You Do Right Now?
If your organization runs Oracle PeopleSoft, here's your action list:
- **Patch immediately** — Check Oracle's latest security updates and apply them without delay. Every hour you wait is an hour attackers have
- **Audit for web shells** — Look for suspicious files, unexpected processes, or unusual outbound connections on your servers
- **Review WAF logs carefully** — Don't just trust the alerts. Dig into the raw traffic for anything that looks slightly off
- **Segment your network** — Limit what an attacker can reach even if they do get in
- **Monitor for lateral movement** — Once inside, attackers rarely stop at one system
### The Bigger Picture
This isn't just an Oracle problem. It's a reminder that enterprise software — the backbone of most large organizations — remains a prime target. These platforms are complex, deeply integrated, and often running versions that haven't been updated in years.
Attackers know this. They count on it.
The organizations that come through incidents like this unscathed aren't the ones with the fanciest tools. They're the ones that patch fast, monitor constantly, and never assume they're too small or too obscure to be targeted.
Because in 2026, that assumption is the most dangerous vulnerability of all.