
Google Warns of Mass Exploitation of Critical Oracle PeopleSoft Vulnerability by ShinyHunters
CybersecurityVulnerabilitiesHackingData BreachOraclePeopleSoftShinyHuntersRemote Code ExecutionWAFWeb Shells
Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft targeting multiple sectors globally. The campaign is linked to ShinyHunters and involves weaponization of CVE-2026-35273, a critical vulnerability with a CVSS score of 9.8 that could result in unauthenticated remote code execution. The vulnerability was first exploited as a zero-day. Attackers are bypassing web application firewalls (WAFs) to exploit the flaw and deploy web shells.