ShinyHunters use URL-encoding WAF bypass on Oracle PeopleSoft CVE-2026-35273
The ShinyHunters extortion gang exploited a URL-encoding technique to bypass web application firewall protections against CVE-2026-35273 in Oracle PeopleSoft, resuming attacks as of September 28, 2026. Security experts urged organizations to apply available patches.