Google warned that a coordinated effort led by the ShinyHunters group is exploiting CVE-2026-35273. The flaw, rated 9.8 on the CVSS scale, lets attackers bypass web application firewalls and gain full system control. The campaign targets finance, education, and government sectors worldwide.
The vulnerability stems from improper input validation in PeopleSoft’s web interface. The attackers craft specially formed requests that evade standard firewalls, then upload web shells to maintain persistent access.
Google's threat intelligence team observed the campaign intensifying in August, targeting finance, education, and government sectors. The attackers use automated scripts to scan for unpatched PeopleSoft instances, then exploit the flaw to inject code. The malicious payloads are delivered via compromised web pages, and the resulting web shells provide remote command access to the compromised servers.
Because many organizations rely on default firewall rules, the malicious traffic blends with legitimate requests, evading detection. This stealth allows the web shells to persist undetected for weeks. The compromised systems remain online for weeks, giving attackers ample time to exfiltrate data or launch further attacks.
The breach could expose sensitive employee data, disrupt services, and lead to regulatory penalties. Experts advise immediate patching, network segmentation, and continuous monitoring to mitigate future attacks. Continued exploitation could damage reputation and trigger legal consequences for affected firms.
What is CVE-2026-35273? It is a critical vulnerability in Oracle PeopleSoft’s web interface that allows remote code execution. The flaw arises from insufficient input validation, enabling attackers to execute arbitrary commands.
How do attackers bypass web application firewalls to deploy web shells? They craft requests that mimic legitimate traffic, exploiting the flaw’s input handling. This evasion lets malicious payloads reach the server and install persistent web shells.
Which sectors are most targeted by this campaign? Finance, education, and government entities have reported the highest infection rates, according to Google’s analysis. The attackers tailor payloads to each industry’s typical PeopleSoft usage.