Google Flags Global Campaign Exploiting Critical Oracle PeopleSoft Flaw
Google's Threat Analysis Group has issued a fresh warning about a wave of attacks that exploit a high‑severity vulnerability in Oracle PeopleSoft, identified as CVE‑2026‑35273 and rated 9.8 on the CVSS scale. The advisory notes that the flaw is being leveraged in a coordinated, large‑scale campaign that spans multiple regions and industry sectors.
The vulnerability enables unauthenticated actors to bypass traditional web‑application firewalls and plant malicious web shells on vulnerable PeopleSoft servers. Once a shell is in place, attackers can execute arbitrary code, move laterally within the network, and exfiltrate data.
Open‑source intelligence links the activity to a threat actor that operates under the name ShinyHunters, a group known for publishing exploit kits and trading compromised credentials on underground forums. The group's signature tactics include rapid weaponization of newly disclosed bugs and the distribution of ready‑to‑use payloads.
According to Google's report, the campaign has affected organizations in finance, healthcare, manufacturing, and government, with incidents reported across North America, Europe and parts of Asia. The breadth of the targeting suggests a motive beyond opportunistic crime, potentially aiming to harvest valuable intellectual property and personal data from high‑value enterprises.
Security researchers point out that PeopleSoft installations are often legacy systems that receive less frequent updates, leaving many enterprises exposed despite Oracle having released patches months ago. The challenge of maintaining compliance for aging applications has contributed to a sizable attack surface.
Google advises immediate remediation: apply Oracle's latest security patches, restrict public access to PeopleSoft portals, and implement network segmentation to limit exposure. Additional measures include monitoring for known web‑shell signatures and employing intrusion‑detection systems that can flag anomalous traffic patterns. The advisory underscores the ongoing risk posed by unpatched enterprise software and the need for continuous vigilance across the supply chain.
Comments (0)
Be the first to comment.
Join the discussion