#1
The Hacker News
general
September 26, 2026 at 11:46 UTC
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
By [email protected] (The Hacker News)
AI Summary
Google is tracking mass exploitation of CVE-2026-35273 (CVSS 9.8), a critical unauthenticated RCE vulnerability in Oracle PeopleSoft, linked to ShinyHunters. The campaign targets multiple sectors globally and involves web shell deployment. Security teams running PeopleSoft should treat this as an active incident-response priority given the critical severity and widespread targeting.
Relevance score: 92.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →