Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
Summary
Attackers are actively exploiting a critical vulnerability in Oracle PeopleSoft, identified as CVE-2026-35273, with a CVSS score of 9.8. This flaw allows for unauthenticated remote code execution and is being used to deploy web shells after bypassing Web Application Firewalls (WAFs).
IFF Assessment
The exploitation of a critical vulnerability enabling unauthenticated remote code execution is a direct threat to organizations using Oracle PeopleSoft.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: June 15, 2026. Known ransomware use: Known.
Defender Context
Defenders need to be aware of active exploitation campaigns targeting Oracle PeopleSoft, specifically the CVE-2026-35273 vulnerability. Prioritizing patching and ensuring WAFs are properly configured to detect and block attempts to exploit this flaw are crucial steps.