Technology newsroom
Urgent Alert: New Oracle PeopleSoft Attacks Bypass WAFs, Install Web Shells
Google warns of a major attack campaign exploiting a critical Oracle PeopleSoft vulnerability (CVE-2026-35273) to bypass WAFs and implant remote Web Shells. System administrators must update patches urgently.
Key Takeaways:
- Google has issued a warning about a major global attack campaign targeting a critical security vulnerability in Oracle PeopleSoft.
- Hackers are exploiting CVE-2026-35273 (CVSS 9.8), which allows remote code execution without authentication.
- The attack technique is sophisticated, enabling bypass of Web Application Firewalls (WAFs) to successfully implant Web Shells for server control.
Google has announced a major resurgence of attacks exploiting a previously discovered security vulnerability in Oracle PeopleSoft. This campaign targets various organizations across sectors globally, causing significant concern among system administrators.
The attack is linked to the notorious hacker group ShinyHunters and leverages CVE-2026-35273, a critical vulnerability with a high CVSS score of 9.8. This flaw allows malicious actors to execute arbitrary code remotely (Remote Code Execution) on victim servers without any authentication process whatsoever.
Attack Techniques and Impact
Most concerningly, attackers have developed techniques to bypass Web Application Firewalls (WAFs), which are a critical frontline defense for web applications. Once the WAF is breached, hackers proceed to install Web Shells β malicious scripts embedded on the server β enabling them to gain control, issue commands, or exfiltrate critical data from the system at any time. This vulnerability has previously been exploited as a Zero-day, underscoring its dangerous nature.
Urgent Action for Administrators
For organizations still using Oracle PeopleSoft, it is urgent to review and apply the latest security patches released by Oracle to address this vulnerability immediately. Reliance solely on WAFs may no longer be sufficient to prevent this type of attack. Therefore, log inspection and scanning for potential compromise should also be conducted.
Does your organization regularly review and update security patches for Oracle systems or other critical applications? Share your practices.