Attackers are exploiting a critical Oracle PeopleSoft vulnerability to bypass web application firewalls and install web shells across multiple sectors worldwide, according to a warning issued by Google. The campaign connects to the ShinyHunters threat actor group, known for large-scale data theft operations and ransomware activity.
The flaw in question is CVE-2026-35273, rated 9.8 on the CVSS scale. This vulnerability enables unauthenticated remote code execution, meaning attackers need no valid credentials to gain control of affected systems. The bug resides in Oracle PeopleSoft, enterprise resource planning software used by thousands of organizations for human resources, payroll, and financial management functions.
Google's security researchers detected renewed exploitation activity after the vulnerability was initially disclosed. The attackers weaponized the flaw to deploy web shells. These persistent backdoors allow attackers to maintain access to compromised servers, execute arbitrary commands, and exfiltrate sensitive data.
The technical sophistication here centers on WAF bypass techniques. Web application firewalls typically block malicious requests at the application layer. The attackers in this campaign developed methods to circumvent these defenses, allowing their exploit code to reach vulnerable PeopleSoft instances undetected. This suggests attackers tailored their payloads to evade signature-based detection rules commonly deployed by WAF vendors.
Oracle PeopleSoft deployments span finance, healthcare, manufacturing, retail, and government sectors. Organizations running unpatched instances face immediate risk. The combination of unauthenticated access and code execution severity means attackers can compromise systems without any internal access or social engineering prerequisite.
ShinyHunters has operated since at least 2020, initially gaining notoriety for breaching Fortune 500 companies and selling stolen databases on dark web forums. The group later shifted tactics, incorporating ransomware deployment and extortion alongside data theft. Their involvement in this PeopleSoft campaign indicates they are actively scanning for vulnerable instances at scale and packaging exploitation as a revenue-generating operation.
The deployment of web shells serves multiple purposes. Attackers use them to maintain persistent access for lateral movement within corporate networks, establish pivot points for additional compromise, and stage ransomware deployment. Organizations that discovered web shells in prior breach investigations often traced back to PeopleSoft exploitation as the initial entry vector.
Oracle released patches for CVE-2026-35273 through its regular security update cycle. However, patching adoption varies significantly across enterprise environments. Legacy PeopleSoft deployments running older versions often remain unpatched due to compatibility concerns or resource constraints. This creates a persistent attack surface that ShinyHunters and similar groups continue to exploit.
Detection requires network monitoring for suspicious outbound connections from PeopleSoft servers, log analysis for unusual web application activity, and file integrity monitoring to identify web shell placement. Organizations should review WAF rules to ensure they capture exploitation attempts targeting PeopleSoft servlets and components.
Immediate actions include identifying all PeopleSoft instances in your environment, checking patch status against Oracle's security bulletins, and applying updates where deployed. For systems requiring extended timelines to patch, implementing network segmentation to restrict PeopleSoft server outbound connectivity and enhanced logging of administrative activities provides interim protection.
