Threat Intelligence

Attackers Bypass Firewalls to Exploit Critical Oracle PeopleSoft Flaw

The Hacker News · 26 Sept 2026
Key Takeaway Businesses running Oracle PeopleSoft should apply available patches immediately and not rely solely on web application firewalls, as attackers are actively bypassing them.

Google has warned of a renewed wave of mass exploitation targeting a critical Oracle PeopleSoft vulnerability, tracked as CVE-2026-35273, which carries a severity score of 9.8 out of 10 and allows unauthenticated attackers to remotely run code on affected systems. The flaw was first exploited as a zero-day against academic institutions, where attackers conducted reconnaissance, installed remote access tools, moved between internal systems, and stole data.

According to Google-owned Mandiant, the group behind the activity, tracked as UNC6240 and linked to ShinyHunters, has now modified its exploit to slip past web application firewalls (WAFs) designed to block access to the vulnerable endpoint. By encoding a single character in the web request, the attackers make the request appear harmless to the firewall, while the PeopleSoft server still decodes and processes it correctly, routing the request to the vulnerable component.

The latest campaign has affected organisations in higher education, technology, healthcare, agriculture, transportation, and government sectors, with web shells planted on dozens of systems. Investigators found that around a quarter of the attacker's commands were run with the highest level of system privileges, giving them extensive control over compromised machines.

Oracle PeopleSoft vulnerability web application firewall bypass

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.