
ShinyHunters Bypass WAF Protections to Resume Exploitation of Oracle PeopleSoft Zero-Day
The ShinyHunters extortion group is actively exploiting a critical Oracle PeopleSoft vulnerability (CVE-2026-35273) by utilizing URL-encoding techniques to bypass existing WAF mitigations. This development follows a series of high-profile zero-day disclosures throughout September 2026.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Critical
- Actor Type:
- Cybercriminal
- Geography:
- Global
- Confidence:
- Confirmed
- CVE:
- CVE-2026-35273
- Source:
- Bleeping Computer
- Read Time:
- 4 min
Executive Summary
As of September 26, 2026, the notorious extortion group ShinyHunters has been observed bypassing Web Application Firewall (WAF) rules designed to mitigate the critical Oracle PeopleSoft vulnerability, CVE-2026-35273. Despite initial patches and security advisories, the group is successfully leveraging URL-encoding obfuscation to execute unauthorized commands on vulnerable servers, leading to ongoing data theft campaigns.
Threat Analysis
ShinyHunters continues to demonstrate high operational agility by adapting their exploit chains to circumvent defensive controls. The group is specifically targeting organizations that have applied standard WAF rules but failed to implement the underlying vendor patches or deep packet inspection required to neutralize encoded payloads. This activity highlights a persistent trend in 2026 where threat actors rapidly weaponize known vulnerabilities that have been partially mitigated.
Technical Details
The vulnerability, CVE-2026-35273, is a critical remote code execution (RCE) flaw within the Oracle PeopleSoft Suite. The exploit allows unauthenticated attackers to gain full control over the application server. ShinyHunters has refined their attack vector by injecting malicious payloads using non-standard URL encoding, which effectively masks the exploit signature from legacy WAF configurations. Once the WAF is bypassed, the payload is decoded by the PeopleSoft application, triggering the RCE condition.
Attribution Assessment
ShinyHunters remains a primary actor in this campaign. Their methodology is consistent with previous data extortion operations, focusing on high-value enterprise software targets. The group’s ability to pivot quickly after security disclosures suggests a well-resourced team capable of reverse-engineering patches and testing bypasses against common security appliances.
Implications
The continued exploitation of CVE-2026-35273 poses a severe risk to enterprise data integrity and confidentiality. Organizations relying solely on perimeter WAF defenses without ensuring that the PeopleSoft environment is fully patched are at high risk of compromise. This incident underscores the limitations of signature-based detection in the face of sophisticated obfuscation techniques.
Recommendations
- Immediate Patching: Ensure all Oracle PeopleSoft instances are updated to the latest security baseline provided by the vendor.
- WAF Tuning: Update WAF rulesets to include advanced normalization and decoding logic to detect URL-encoded malicious payloads.
- Threat Hunting: Monitor server logs for suspicious URL-encoded strings and unauthorized outbound connections originating from PeopleSoft application servers.
- Incident Response: Review access logs for signs of unauthorized administrative activity and initiate credential rotation if compromise is suspected.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

ShinyHunters Resumes Exploitation of Oracle PeopleSoft via WAF Bypass Technique

Critical Zero-Day Vulnerability CVE-2026-93616 Exploited in Check Point Security Management Infrastructure

