Skip to main content
CyberReportedHighDevelopingFeatured
7.0

ShinyHunters bypasses WAF to exploit Oracle PeopleSoft CVE-2026-35273

ShinyHunters is using a URL-encoding trick to bypass WAF rules for CVE-2026-35273, resuming widespread exploitation of vulnerable Oracle PeopleSoft servers. The bypass undermines existing mitigations, increasing risk for unpatched organizations. The full scope of affected systems remains unclear.

BleepingComputerabout 3 hours agoengCredibility 19%View source

Score Breakdown

Mosaic Score7.0
Model confidence0.7
Significance0.8
Source credibility0.2
Source

Related signals

8 found