Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Summary

Attackers are actively exploiting a critical vulnerability in Oracle PeopleSoft, identified as CVE-2026-35273, with a CVSS score of 9.8. This flaw allows for unauthenticated remote code execution and is being used to deploy web shells after bypassing Web Application Firewalls (WAFs).

IFF Assessment

FOE

The exploitation of a critical vulnerability enabling unauthenticated remote code execution is a direct threat to organizations using Oracle PeopleSoft.

Severity

9.8 Critical

CISA KEV: Listed as actively exploited. Federal patch due: June 15, 2026. Known ransomware use: Known.

Defender Context

Defenders need to be aware of active exploitation campaigns targeting Oracle PeopleSoft, specifically the CVE-2026-35273 vulnerability. Prioritizing patching and ensuring WAFs are properly configured to detect and block attempts to exploit this flaw are crucial steps.

Read Full Story →