Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Vulnerability in Oracle PeopleSoft Exploited Globally

Critical Vulnerability in Oracle PeopleSoft Exploited Globally

Posted on September 26, 2026 By CWS

Google has issued a warning regarding a widespread exploitation of a significant security flaw in Oracle PeopleSoft, affecting multiple sectors worldwide. This campaign, linked to the ShinyHunters group, leverages CVE-2026-35273, a vulnerability with a critical CVSS score of 9.8, enabling unauthorized remote code execution.

Global Impact of the Oracle PeopleSoft Exploit

The vulnerability, initially exploited as a zero-day, primarily targeted educational institutions, where attackers conducted reconnaissance, deployed remote access tools like MeshCentral, and exfiltrated data. Google’s Mandiant had alerted over 100 organizations globally about potential risks, with most affected entities based in the U.S.

The recent wave of attacks shows the involvement of threat actor UNC6240, who managed to bypass web application firewall (WAF) protections by URL-encoding characters in the request path. This manipulation allows the attackers to exploit the Environment Management Hub (PSEMHUB) endpoint, circumventing defenses designed to block such intrusions.

Methodology of the Exploitation

The attackers targeted several sectors, including technology, healthcare, and government, deploying web shells across numerous systems. The attack sequence involved identifying vulnerable targets via POST requests containing serialized Java objects and bypassing WAFs using encoded characters.

Once through the defenses, the attackers exploited Java deserialization vulnerabilities to deploy web shells and execute commands without detection. They planted two JSP web shells in critical directories to facilitate cross-platform commands and upload tools like the trojanized installer Ple64.exe, which introduced a C++ backdoor for credential theft and system control.

Preventive Measures and Future Outlook

To mitigate this threat, organizations are urged to patch the CVE-2026-35273 vulnerability promptly, disable or remove the vulnerable services, and scrutinize access logs for anomalous activity. Further, they should inspect directories for malicious files, rotate credentials, and monitor network traffic for unusual patterns.

Google highlights the pattern of extortion by UNC6240, emphasizing the need for vigilance against data theft and potential public data exposure. Recent incidents, such as the breach of FBIJobs.gov, underscore the group’s continued attempts to exploit vulnerabilities, although they deny financial motives.

As cyber threats evolve, organizations must remain proactive in strengthening their defenses to protect sensitive data and prevent unauthorized access, underscoring the importance of continuous monitoring and timely updates to security protocols.

The Hacker News Tags:CVE-2026-35273, cyber attack, Cybersecurity, data theft, Extortion, Oracle PeopleSoft, remote code execution, ShinyHunters, Vulnerability, WAF bypass, web security

Post navigation

Previous Post: Kiteworks Recommends Nine-Hour System Shutdown Amid Cyber Threat

Related Posts

SonicWall Confirms State-Sponsored Hackers Behind September Cloud Backup Breach SonicWall Confirms State-Sponsored Hackers Behind September Cloud Backup Breach The Hacker News
CISA Flags Meteobridge CVE-2025-4008 Flaw as Actively Exploited in the Wild CISA Flags Meteobridge CVE-2025-4008 Flaw as Actively Exploited in the Wild The Hacker News
Moldovan Police Arrest Suspect in €4.5M Ransomware Attack on Dutch Research Agency Moldovan Police Arrest Suspect in €4.5M Ransomware Attack on Dutch Research Agency The Hacker News
Bootkit Malware, AI-Powered Attacks, Supply Chain Breaches, Zero-Days & More Bootkit Malware, AI-Powered Attacks, Supply Chain Breaches, Zero-Days & More The Hacker News
CISA Alerts on N-able N-central Vulnerability Exploitation CISA Alerts on N-able N-central Vulnerability Exploitation The Hacker News
Fake Kling AI Facebook Ads Deliver RAT Malware to Over 22 Million Potential Victims Fake Kling AI Facebook Ads Deliver RAT Malware to Over 22 Million Potential Victims The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Vulnerability in Oracle PeopleSoft Exploited Globally
  • Kiteworks Recommends Nine-Hour System Shutdown Amid Cyber Threat
  • New Botnet x47.c Leverages AI for Advanced Cyber Attacks
  • SharePoint and MikroTik Vulnerabilities Exploited
  • Teen Researcher Uncovers Major Microsoft Data Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Vulnerability in Oracle PeopleSoft Exploited Globally
  • Kiteworks Recommends Nine-Hour System Shutdown Amid Cyber Threat
  • New Botnet x47.c Leverages AI for Advanced Cyber Attacks
  • SharePoint and MikroTik Vulnerabilities Exploited
  • Teen Researcher Uncovers Major Microsoft Data Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark