Skip to content
feed: live
>_0dayNews
oracle
● Breaking

ShinyHunters Retooled PeopleSoft Exploit, Google Warns

Google warns ShinyHunters has retooled its CVE-2026-35273 exploit and is running a fresh campaign against Oracle PeopleSoft. Patch or take exposed instances offline now.

ShinyHunters Retooled PeopleSoft Exploit, Google Warns
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
fuseMarisol "Fuse" Delgado·Published ·1 min read

Google Threat Intelligence Group issued a warning on September 28, 2026: ShinyHunters has retooled its exploit for CVE-2026-35273 and is running a fresh attack campaign against Oracle PeopleSoft environments. The group modified its tooling to sustain access after earlier defensive measures slowed prior waves, according to SecurityWeek’s reporting on Google’s assessment.

CVE-2026-35273 is a CVSS 9.8 missing-authentication flaw in Oracle PeopleSoft Enterprise PeopleTools. An unauthenticated attacker can obtain full system takeover. CISA added it to the Known Exploited Vulnerabilities catalog in June 2026 with ransomware use confirmed. The KEV deadline for federal agencies was June 15, 2026.

That modification changes what defenders need to block. Yesterday’s reporting documented a ShinyHunters WAF bypass technique that let the group reach PeopleSoft instances organizations thought were shielded by network-layer controls. A retooled exploit on top of that bypass means teams that blocked the original attack pattern may not be blocking the new one.

ShinyHunters has run multiple campaigns against PeopleSoft since at least late August 2026. The group is iterating on technique rather than pivoting to a new target, which makes prioritization straightforward: PeopleSoft patching stays near the top of the queue until this stops.

What to do

If your PeopleSoft instance is internet-facing and unpatched: take it offline or block external access before doing anything else. This is not a “plan to patch by next change window” situation.

If you are patched: confirm the patch was applied correctly and fully. The WAF bypass reporting from September 27 showed some organizations believed they were protected when they were not. Verify the patched build version against Oracle’s security advisory.

Check your logs regardless of patch status. Look for unauthenticated administrative access, unexpected user creation, and web shell artifacts. A retooled exploit may produce different indicators than the earlier campaign. If you find evidence of compromise, treat it as an incident, not a near-miss.

The CVE-2026-35273 entry has the full technical record and CISA KEV details. For related Oracle exposure in this environment, CVE-2026-21962 in Oracle WebLogic is also KEV-listed and worth verifying.

Related CVEs
  • [ CRITICAL ]CVE-2026-35273Oracle PeopleSoft PeopleTools missing authentication allows unauthenticated takeover

Found this useful? Share it.