Back to all news
Security

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

The Hacker News·September 26, 2026·1 min read
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Google warns of renewed mass exploitation of Oracle PeopleSoft vulnerability CVE-2026-35273 (CVSS 9.8), linked to ShinyHunters. Attackers bypass web application firewalls to deploy web shells, achieving unauthenticated remote code execution. The campaign targets multiple sectors globally, and the flaw was first exploited as a zero-day, posing critical risk to unpatched systems.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store