Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Vulnerability in Oracle PeopleSoft Exploited Globally

Critical Vulnerability in Oracle PeopleSoft Exploited Globally

Posted on September 26, 2026 By CWS

Google has issued a warning regarding a widespread exploitation of a significant security flaw in Oracle PeopleSoft, affecting multiple sectors worldwide. This campaign, linked to the ShinyHunters group, leverages CVE-2026-35273, a vulnerability with a critical CVSS score of 9.8, enabling unauthorized remote code execution.

Global Impact of the Oracle PeopleSoft Exploit

The vulnerability, initially exploited as a zero-day, primarily targeted educational institutions, where attackers conducted reconnaissance, deployed remote access tools like MeshCentral, and exfiltrated data. Google’s Mandiant had alerted over 100 organizations globally about potential risks, with most affected entities based in the U.S.

The recent wave of attacks shows the involvement of threat actor UNC6240, who managed to bypass web application firewall (WAF) protections by URL-encoding characters in the request path. This manipulation allows the attackers to exploit the Environment Management Hub (PSEMHUB) endpoint, circumventing defenses designed to block such intrusions.

Methodology of the Exploitation

The attackers targeted several sectors, including technology, healthcare, and government, deploying web shells across numerous systems. The attack sequence involved identifying vulnerable targets via POST requests containing serialized Java objects and bypassing WAFs using encoded characters.

Once through the defenses, the attackers exploited Java deserialization vulnerabilities to deploy web shells and execute commands without detection. They planted two JSP web shells in critical directories to facilitate cross-platform commands and upload tools like the trojanized installer Ple64.exe, which introduced a C++ backdoor for credential theft and system control.

Preventive Measures and Future Outlook

To mitigate this threat, organizations are urged to patch the CVE-2026-35273 vulnerability promptly, disable or remove the vulnerable services, and scrutinize access logs for anomalous activity. Further, they should inspect directories for malicious files, rotate credentials, and monitor network traffic for unusual patterns.

Google highlights the pattern of extortion by UNC6240, emphasizing the need for vigilance against data theft and potential public data exposure. Recent incidents, such as the breach of FBIJobs.gov, underscore the group’s continued attempts to exploit vulnerabilities, although they deny financial motives.

As cyber threats evolve, organizations must remain proactive in strengthening their defenses to protect sensitive data and prevent unauthorized access, underscoring the importance of continuous monitoring and timely updates to security protocols.

The Hacker News Tags:CVE-2026-35273, cyber attack, Cybersecurity, data theft, Extortion, Oracle PeopleSoft, remote code execution, ShinyHunters, Vulnerability, WAF bypass, web security

Post navigation

Previous Post: Kiteworks Recommends Nine-Hour System Shutdown Amid Cyber Threat
Next Post: Enhancing AI Agent Security with Zero Trust Principles

Related Posts

Why Unmonitored JavaScript Is Your Biggest Holiday Security Risk Why Unmonitored JavaScript Is Your Biggest Holiday Security Risk The Hacker News
Learn How AI-Powered Zero Trust Detects Attacks with No Files or Indicators Learn How AI-Powered Zero Trust Detects Attacks with No Files or Indicators The Hacker News
Verification Steps: The New ATO Challenge in 2026 Verification Steps: The New ATO Challenge in 2026 The Hacker News
Malicious NuGet Package Targets Financial Sector Malicious NuGet Package Targets Financial Sector The Hacker News
Effective Identity Risk Management in Modern Enterprises Effective Identity Risk Management in Modern Enterprises The Hacker News
Mythos’ Impact on Exposure Windows in Security Programs Mythos’ Impact on Exposure Windows in Security Programs The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Enhancing AI Agent Security with Zero Trust Principles
  • Critical Vulnerability in Oracle PeopleSoft Exploited Globally
  • Kiteworks Recommends Nine-Hour System Shutdown Amid Cyber Threat
  • New Botnet x47.c Leverages AI for Advanced Cyber Attacks
  • SharePoint and MikroTik Vulnerabilities Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Enhancing AI Agent Security with Zero Trust Principles
  • Critical Vulnerability in Oracle PeopleSoft Exploited Globally
  • Kiteworks Recommends Nine-Hour System Shutdown Amid Cyber Threat
  • New Botnet x47.c Leverages AI for Advanced Cyber Attacks
  • SharePoint and MikroTik Vulnerabilities Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark