Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
thehackernews.com Sep 26, 2026

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

AI-summarised brief · reviewed before publication

Google warned of a new wave of attacks exploiting Oracle PeopleSoft’s CVE‑2026‑35273, a critical flaw enabling unauthenticated remote code execution. The threat actor, linked to ShinyHunters, bypassed web‑application firewalls by URL‑encoding the request path, allowing deployment of web shells and the Neo‑ReGeorg tunneling toolkit. The campaign targeted diverse sectors—including education, healthcare, and government—using tools such as MeshCentral for persistence and MeshAgent for Linux. Over 100 organizations were notified, and the attackers have executed commands with root or SYSTEM privileges.

💡 Why It Matters

  • · The breach demonstrates how attackers can subvert WAF defenses to gain deep, privileged access across critical infrastructures, underscoring the urgency for robust, application‑level security controls.