Home / Sep 27, 2026 / Story
0
#1 The Hacker News general September 26, 2026 at 11:46 UTC

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

By [email protected] (The Hacker News)

AI Summary

Google is tracking mass exploitation of CVE-2026-35273 (CVSS 9.8), a critical unauthenticated RCE vulnerability in Oracle PeopleSoft, linked to ShinyHunters. The campaign targets multiple sectors globally and involves web shell deployment. Security teams running PeopleSoft should treat this as an active incident-response priority given the critical severity and widespread targeting.

Relevance score: 92.0/100

# More from September 27