Google has issued a warning regarding a resurgence in the exploitation of a severe vulnerability in Oracle PeopleSoft, identified as CVE-2026-35273, which boasts a CVSS score of 9.8. This flaw allows for unauthenticated remote code execution, posing a significant risk to organizations across various sectors. The ongoing campaign, attributed to the ShinyHunters group, underscores the urgency for businesses to address this vulnerability promptly to safeguard their systems against potential breaches.
For organizations utilizing Oracle PeopleSoft, the implications are substantial. The ability for attackers to deploy web shells and execute arbitrary code remotely highlights the need for enhanced security measures, including the review and updating of existing Web Application Firewalls (WAFs) that may be insufficient against this threat. Given the critical nature of this vulnerability, businesses must prioritize patch management and vulnerability assessment strategies to mitigate the risk of exploitation, reinforcing their cybersecurity posture in an increasingly complex threat landscape.
---
*Originally reported by [The Hacker News](https://thehackernews.com/2026/09/attackers-bypass-wafs-to-exploit-oracle.html)*