Blog · Security

Attackers Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

· 2TInteractive · generated daily-pipeline

Attackers Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Google has warned of renewed attacks exploiting a critical flaw in Oracle PeopleSoft, allowing attackers to bypass WAFs and deploy web shells.

Oracle PeopleSoft users are under renewed attack. Google warned of active exploitation of a known critical vulnerability (CVE-2026-35273) in the software. Attackers are deploying web shells after bypassing Web Application Firewalls (WAFs), a strategy linked to the ShinyHunters-linked group. The issue is the unauthenticated remote code execution bug with a CVSS score of 9.8. Attackers can exploit this flaw by using a URL-encoding trick, according to source reports;

The flaw first surfaced as a zero-day vulnerability. This flaw lets attackers run arbitrary code on the affected systems. This attack could impact multiple sectors globally. PeopleSoft is widely used in HRM and Finances. The urgency is clear. Companies rely heavily on enterprise software for managing internal operations. Effective exploitation can lead to data breaches, service disruptions, financial losses, and operational chaos. Attackers often deploy web shells for persistent access, complicating remediation efforts. Many organizations are scrambling to secure their PeopleSoft systems. There is a critical need for immediate action to mitigate the risk.

What happened

Google's Threat Analysis Group (TAG) released a report on September 26, 2026, detailing a campaign targeting multiple sectors globally. The campaign exploits a critical flaw in Oracle PeopleSoft, identified as CVE-2026-35273.

The vulnerability carries a CVSS score of 9.8, indicating a high risk of security breach. This flaw allows attackers to bypass WAFs and execute unauthenticated remote code.

The ShinyHunters extortion gang has been linked to the activity according to The Hacker News. The gang has implemented a URL-encoding trick to circumvent WAF rules.

This tactic enables them to deploy web shells and perform other malicious actions on vulnerable servers according to BleepingComputer.

The attacks involve weaponizing the CVE-2026-35273 flaw, which was initially exploited as a zero-day before being publicly disclosed and patched by Oracle.

Sectors targeted by these exploits include finance, education, governments, and healthcare, according to Google's TAG.

  • "In many recent cases, attackers have also been successful in deploying web shells on the compromised servers. These shells provide attackers with a persistent foothold in the compromised networks," mentioned in The BleepingComputer article.
  • Attackers have used these web shells to exfiltrate sensitive data, deploy additional malware, and gain further access to internal networks.

Multiple incidents have been reported across the globe, with affected organizations rushing to patch their systems. The urgency is heightened by the potential for severe data breaches and operational disruptions.

Affected organizations are advised to apply the latest security patches from Oracle and review their security configurations to prevent further exploiting of the CVE-2026-35273 flaw as suggested by Google TAG.

There are widespread indications that the attackers are actively scanning the internet for vulnerable Oracle PeopleSoft instances.

Many organizations have not yet patched their systems, leaving them exposed to these attacks. According to reports, the attackers are constantly refining their techniques to evade detection and bypass security measures.

"The exploitation attempts have been observed in various regions, with notable activity in North America, Europe, and Asia," disclosed the hackers to The Hacker News.

Organizations should monitor their systems closely for any signs of compromise and take immediate action to mitigate the risk posed by these attacks.

Why it matters

Vulnerabilities in enterprise applications like Oracle PeopleSoft are not just theoretical risks. The ability of attackers to bypass Web Application Firewalls (WAFs) and deploy web shells is a real threat. This latest exploitation of CVE-2026-35273, as reported by The Hacker News, shows that critical flaws can be weaponized with widespread impact. Businesses using PeopleSoft are at immediate risk of unauthorized code execution, data breach, or other malicious activities. IT teams must prioritize patching and monitoring for this specific vulnerability.

The ShinyHunters extortion gang used a URL-encoding trick to bypass WAFs, as detailed by BleepingComputer. This means that even if companies have implemented WAF solutions, they cannot consider themselves fully protected. IT teams must stay aware of emerging bypass techniques and update their defenses accordingly.

  • Widespread attacks. Attacks are targeting multiple sectors globally, making no sector immune. Businesses across industries need to act quickly to prevent breaches.
  • Data theft. A successful exploit could lead to unauthorized access to sensitive data, financial information, and intellectual property.
  • Operational disruption. Deploying web shells can allow attackers to gain control over applications and systems, disrupting critical business operations.
  • Reputation damage. A security breach can significantly impact a company’s reputation, leading to loss of customer trust and potential legal repercussions.

What to do

You need to prioritize multiple actions to secure your systems against Oracle PeopleSoft vulnerabilities.

  • Update Oracle PeopleSoft applications immediately. Patch management is key. Google warns of active exploits. Do not just rely on WAFs.
  • Check for signs of compromise. If your organization uses PeopleSoft, review logs and audit trails. Use these resources to monitor for unusual activities, especially focusing on recent changes or unauthorized access attempts. The sooner you identify a breach, the quicker you can contain it.

    Implement multi-layered security measures. Beyond WAFs, deploy additional security measures such as intrusion detection systems and regular vulnerability scanning. These tools can help identify and mitigate threats more effectively. BleepingComputer notes that the ShinyHunters extortion gang has used URL-encoding tricks to bypass WAF rules. Use WAFs but also enhance your defensive perimeter. Google states that threat actors are actively weaponizing CVE-2026-35273.

    Consider a risk assessment. Work with your IT team to establish comprehensive security policies.

  • Educate your team. Training is crucial. Ensure that your IT team and other relevant personnel are fully aware of the latest threats and response protocols. Emphasize the importance of regular updates and vigilant monitoring.

Protecting against this specific type of attack isn't straightforward. Bypass techniques are difficult for one WAF tool to spot.

Security is all about layers. Multiple checks are essential to maintain a solid defense. Do not underestimate the importance of continuous monitoring. Stay alert to new vulnerabilities and trends.

2TI lens

A Spatial Digital Agency might advise securing the PeopleSoft environment with multi-layered defense, including spatial awareness tools and proactive monitoring, to identify and mitigate threats like CVE-20236-35273. By integrating these systems, organizations could reduce vulnerabilities and respond more swiftly to potential breaches, ensuring both physical and digital security are robust.

< h2>Sources

The Hacker News and BleepingComputer reported this story.

Quick answers

What is the vulnerability in Oracle PeopleSoft?

The vulnerability is CVE-2026-35273, a critical flaw that allows unauthenticated remote code execution.

Who is exploiting this vulnerability?

The ShinyHunters extortion gang is exploiting this vulnerability by bypassing WAFs.

What is the impact of this vulnerability?

The vulnerability could result in unauthorized access and control over vulnerable servers globally.