ShinyHunters is using a URL-encoding trick to bypass WAF rules and exploit Oracle PeopleSoft flaw CVE-2026-35273. Learn how to protect your servers.
### The ShinyHunters WAF Bypass: A New Twist in Oracle PeopleSoft Attacks
Imagine you've locked your front door with the best deadbolt money can buy. Then someone walks around back and slips through a window you forgot to close. That's essentially what the ShinyHunters extortion gang is doing with Oracle PeopleSoft servers right now.
According to recent reports, the group has figured out a URL-encoding trick that lets them slip past web application firewall (WAF) rules designed to block attacks on a critical vulnerability tracked as CVE-2026-35273. By encoding malicious requests in a way the WAF doesn't recognize, they can resume widespread exploitation of unpatched servers. It's a clever, sneaky move—and it's catching a lot of organizations off guard.
### Why This Bypass Matters
Web application firewalls are supposed to be the bouncer at the door, checking every request that comes in. They look for known attack patterns and block anything suspicious. But attackers are constantly finding ways to disguise their payloads.
In this case, the URL-encoding trick essentially changes how the request looks to the WAF, so the firewall doesn't see the malicious payload. The server, however, still understands it—and executes the attack. That's the dangerous part.
- **WAFs aren't foolproof:** They're a layer of defense, not a magic shield.
- **Patching is still critical:** The underlying flaw (CVE-2026-35273) needs to be fixed at the source.
- **Attackers adapt fast:** As soon as one bypass is blocked, they'll look for another.
### What Is CVE-2026-35273?
Without getting too deep into the weeds, CVE-2026-35273 is a vulnerability in Oracle PeopleSoft that allows attackers to execute code or access sensitive data remotely. Oracle released a patch, but many organizations haven't applied it yet—either because of compatibility concerns, downtime fears, or just plain old procrastination.
ShinyHunters is known for extortion: they break in, steal data, and demand payment to keep it quiet. So if they're actively exploiting this flaw, it's not just a theoretical risk. It's happening.
### How to Protect Your PeopleSoft Environment
If you're running Oracle PeopleSoft, here's what you should do right now:
1. **Patch immediately.** Apply Oracle's fix for CVE-2026-35273. Don't wait for the next maintenance window if you can help it.
2. **Review your WAF rules.** Make sure they're up to date and consider adding custom rules to catch URL-encoding anomalies.
3. **Monitor for suspicious activity.** Look for unusual requests, especially those with encoded characters in unexpected places.
4. **Segment your network.** Limit lateral movement if an attacker does get in.
5. **Have an incident response plan.** If you haven't tested it lately, now's the time.
### The Bigger Picture
This isn't just about one gang and one vulnerability. It's a reminder that security is a moving target. Attackers are creative, patient, and increasingly sophisticated. A WAF alone won't save you. You need defense in depth: patching, monitoring, segmentation, and a team that knows what to do when things go wrong.
> "Security is not a product, but a process." — Bruce Schneier
That quote rings especially true here. ShinyHunters found a gap in the process. The question is: will you close it before they come back?
### Final Thoughts
The ShinyHunters WAF bypass is a wake-up call. If you're responsible for Oracle PeopleSoft or any critical application, take this seriously. Patch, monitor, and stay vigilant. Because the bad guys aren't waiting—and neither should you.