ShinyHunters use URL-encoding WAF bypass on Oracle PeopleSoft CVE-2026-35273

The ShinyHunters extortion gang exploited a URL-encoding technique to bypass web application firewall protections against CVE-2026-35273 in Oracle PeopleSoft, resuming attacks as of September 28, 2026. Security experts urged organizations to apply available patches.

5 reportsother · tech

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

rss:bleepingcomputertech3d ago kagi ↗

The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers. [...]

The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume wid

mastodon:infosec-exchangeother3d ago kagi ↗

The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers. https://www. bleepingcomputer.com/news/secu rity/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks/

The ShinyHunters extortion gang is using a URL-encoding trick to bypass WAF rules protecting Oracle PeopleSoft servers from the CVE-2026-35273 vulnerability. Experts urge organizations to apply the la

mastodon:infosec-exchangeother2d ago kagi ↗

The ShinyHunters extortion gang is using a URL-encoding trick to bypass WAF rules protecting Oracle PeopleSoft servers from the CVE-2026-35273 vulnerability. Experts urge organizations to apply the latest security updates rather than relying on firewall mitigations to prevent further data theft and web shell deployments. https://www. bleepingcomputer.com/news/secu rity/shinyhunters-uses-waf-bypass