The hacking group ShinyHunters exploited CVE-2026-35273, a critical unauthenticated remote code execution vulnerability in Oracle PeopleSoft, using URL-encoding tricks to bypass web application firewalls. By 2026-09-28, ShinyHunters claimed responsibility for breaching the FBI.
6 reportsother
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
Google’s Mandiant team warned of renewed exploitation by ShinyHunters of CVE-2026-35273, a critical Oracle PeopleSoft flaw that can enable unauthenticated remote code execution. The campaign targets unpatched servers across multiple sectors, Mandiant said [thehackernews.com#1][bleepingcomputer.com#1].
🤖 Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8, unauthenticated RCE) is being mass-exploited again by ShinyHunters. Attackers use URL-encoding tricks to bypass WAF rules meant to block the flaw, then drop web shells. Google warns of global multi-sector targeting. 🔗 https:// thehackernews.com/2026/09/atta ckers-bypass-wafs-to-exploit-oracle.html # CVE # Exploit # 0day # InfoSec # WebShell
🤖 Oracle PeopleSoft CVE-2026-35273 (unauth RCE) actively exploited: ShinyHunters now percent-encodes the path — /%50SEMHUB/ — so WAF rules matching the literal path miss it, while WebLogic decodes and still routes there. New data theft across dozens of orgs. Patch; then grep logs for /%50SEMHUB/. 🔗 https://www. bleepingcomputer.com/news/secu rity/shinyhunters-uses-waf-bypass-trick-in-oracle-peop
🔵 THREAT INTELLIGENCE Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells Vulnerability | CRITICAL CVEs: CVE-2026-35273 Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple... Full analysis: https://www. yazoul.net/news/article/attack ers-bypass-wafs-to-exploit-oracle-peoplesoft-fla