Interestana
Home/News/Attackers Exploit Oracle PeopleSoft Flaw, Deploy Web Shells
The Hacker News••3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Attackers Exploit Oracle PeopleSoft Flaw, Deploy Web Shells

Attackers Exploit Oracle PeopleSoft Flaw, Deploy Web Shells

Google is alerting organizations to a resurgence in the mass exploitation of a critical security vulnerability within Oracle PeopleSoft, a widely used enterprise resource planning (ERP) software. This renewed campaign, linked to threat actors associated with the ShinyHunters group, targets multiple sectors globally and involves the weaponization of CVE-2026-35273. This specific vulnerability carries a high CVSS score of 9.8, indicating its critical severity and potential for unauthenticated remote code execution. The exploitation of this flaw allows attackers to gain unauthorized control over affected systems.

The primary objective of these attacks appears to be the deployment of web shells on compromised Oracle PeopleSoft instances. Web shells are malicious scripts that attackers use to establish a backdoor into a system, enabling them to execute commands remotely, access sensitive data, and potentially move laterally within the network. The attackers are reportedly bypassing Web Application Firewalls (WAFs) to achieve this unauthorized access, suggesting sophisticated techniques are being employed to circumvent standard security measures. The vulnerability was initially exploited as a zero-day, meaning it was actively exploited by attackers before Oracle had released a patch or publicly disclosed the flaw, highlighting the challenges in defending against such advanced persistent threats.

Oracle PeopleSoft is a comprehensive suite of applications designed to manage human resources, financial management, supply chain management, and customer relationship management for large enterprises. Its widespread adoption across various industries, including higher education, government, and finance, makes it a significant target for cybercriminals. The exploitation of a critical vulnerability like CVE-2026-35273 can have far-reaching consequences, potentially leading to data breaches, service disruptions, and significant financial losses for affected organizations. The fact that this vulnerability is being actively exploited again, even after its initial discovery, underscores the persistent threat landscape and the need for continuous vigilance and prompt patching of known security weaknesses.

Google's warning serves as a critical alert for organizations utilizing Oracle PeopleSoft to immediately assess their systems for signs of compromise and to ensure that all relevant security patches and updates are applied. The ability of attackers to bypass WAFs suggests that organizations may need to review and enhance their perimeter defenses and intrusion detection systems. The ongoing nature of these attacks, as indicated by the "renewed mass exploitation," implies that the threat actors are actively seeking out vulnerable systems and are prepared to leverage known exploits to achieve their objectives. The critical nature of the vulnerability and the potential for remote code execution necessitate a swift and comprehensive response from all affected entities to mitigate the risk of further compromise.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next