Attackers Bypass Firewalls to Exploit Critical Oracle PeopleSoft Flaw
Google has warned of a renewed wave of mass exploitation targeting a critical Oracle PeopleSoft vulnerability, tracked as CVE-2026-35273, which carries a severity score of 9.8 out of 10 and allows unauthenticated attackers to remotely run code on affected systems. The flaw was first exploited as a zero-day against academic institutions, where attackers conducted reconnaissance, installed remote access tools, moved between internal systems, and stole data.
According to Google-owned Mandiant, the group behind the activity, tracked as UNC6240 and linked to ShinyHunters, has now modified its exploit to slip past web application firewalls (WAFs) designed to block access to the vulnerable endpoint. By encoding a single character in the web request, the attackers make the request appear harmless to the firewall, while the PeopleSoft server still decodes and processes it correctly, routing the request to the vulnerable component.
The latest campaign has affected organisations in higher education, technology, healthcare, agriculture, transportation, and government sectors, with web shells planted on dozens of systems. Investigators found that around a quarter of the attacker's commands were run with the highest level of system privileges, giving them extensive control over compromised machines.