EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Editorial source
Editorial OSINT source. The content is an indication to verify with independent institutional or technical sources before operational decisions.
EudorIA operational summary

What it means

Priority 95/100

Attacker bypass WAFs to exploit Oracle PeopleSoft CVE-2026-35273, deploying web shells and backdoors. The exploit uses URL encoding to bypass WAF rules. Targets include education, healthcare, and government sectors. Patching and disabling the PSEMHUB service are critical. Threat actors use MeshAgent for persistence and steal data for potential extortion.

Why it matters

PMI italiane in settori come sanità e istruzione sono a rischio di furto dati e ransoming. La vulnerabilità è critica e sfruttata in modo massiccio, con impatto grave sulla reputazione e sulla continuità operativa.

Potential operational benefits

  • Riduzione della superficie esposta alle minacce
  • Miglioramento della rilevazione e risposta agli attacchi
  • Protezione dei dati sensibili e prevenzione del ransoming
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsPatch managementSegmentazione di reteMonitoraggio / SIEMEDR / XDRBackup & DR
AudienceITSOCCISO
Information centre

Translation in progress

The Hacker News

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution. The vulnerability was first exploited as a zero-day

Source
The Hacker News
Publishing entity
The Hacker News
Entity type
editorial osint
Area
Global
Original language
en · translation in preparation
Publication
26/09/2026 13:46
MITRE ATT&CK
T1190, T1078, T1486
CVE
CVE-2026-35273
Classification
Critical
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Open the original source