Google’s warning landed on a box most of you still treat as plumbing. Oracle PeopleSoft. HR. Campus. Procurement. The portal finance actually uses on Monday morning. Researchers tracking CVE-2026-35273, a 9.8 unauthenticated remote code execution flaw, watched it return as mass exploitation across sectors. ShinyHunters-linked operators were in that traffic. They bypassed web application firewalls and dropped web shells. Your cybersecurity stack already had a green tile for threat-protection at the edge. The ERP was serving a listener.

Google called a number you already knew
This campaign did not need a brand-new bug. CVE-2026-35273 had already been exploited as a zero-day. A patch exists now, which in most shops starts a calendar fight between Oracle’s CPU schedule and the team that owns the portal. Google is watching the same flaw used at scale, across multiple sectors, with web shells as the payload of choice. Unauthenticated RCE in PeopleSoft is a clean win for an operator. No stolen password. No MFA prompt. No brute-force spray for the SOC to screenshot. A reachable instance takes a request, code runs, and a shell lands in a directory the app server will execute.
WAF bypass sits in that picture as tradecraft. People who do this work for a living probe encodings, odd content types, split bodies, and header tricks until the proxy stops arguing and the origin answers. Count 403s on the reverse proxy if you want a dashboard. Hunt the PeopleSoft host if you want the truth.
A web shell on an ERP is persistence with a business login page in front of it. It sits next to integration brokers, report servers, and the service accounts that talk to campuses, vendors, and payroll files. Treat that host like a domain controller that happens to wear a portal skin.
ShinyHunters-linked activity is the part that should make executives sit up. Crews in that orbit have spent years turning access into leak sites and extortion. An ERP web shell is a shortcut to HR files, supplier records, and the identity data every other system trusts. You are looking at a beachhead that already knows how to bill you for the copy.
Enterprise cybersecurity still ends at the proxy
Plenty of programs still describe defense in depth as a firewall, a WAF, and a slide that says the app team owns PeopleSoft. That split is how a 9.8 lives into the next quarter. Edge gear is tuned for credential stuffing and the brute-force patterns that ship in default rule packs. Remote code execution against an application server looks like a successful page load.
CISA spent the same week adding a Microsoft SharePoint code injection flaw, CVE-2026-65660, to the Known Exploited Vulnerabilities catalog, with a MikroTik RouterOS bug riding along, because both are already being used. SharePoint is the other portal you cannot turn off for a quiet patch window. PeopleSoft and SharePoint rhyme: business apps with low-friction code execution, active exploitation, and a political argument against isolation.

Cyber security leadership still draws a diagram where the dangerous internet stops at a box you purchased. These portals live on ordinary app servers, with file systems, scheduled jobs, and credentials that reach the directories and databases the rest of the company trusts. Enterprise cybersecurity that ends at the proxy is a budget line with a logo on it. This is a bad look for any program that still briefs the board on WAF block rates while PeopleSoft answers the open internet.
Hunt the shell while the patch window is still open
If you run PeopleSoft on a network you can actually diagram, start now.
Inventory every instance. Production, disaster recovery, the temporary refresh environment from last year’s audit, campus portals, and vendor-hosted boxes you still authenticate into. Anything speaking PeopleSoft on 443 outside a tight jump path is in scope. Verify CVE-2026-35273 is patched by reading the build on the host.
Assume a shell until a known-good comparison says otherwise. In this stack, unexpected JSP, class, or script files under the application server deploy paths are the tell, especially names that do not match your last legitimate package and write times that do. Diff against the installer. Watch the web container’s process tree for cmd, powershell, bash, or curl. Align those timestamps with unauthenticated POSTs that returned 200.
Pull a hashed file listing of the web root and PS_HOME-style trees into the ticket so the next investigator is not starting from a live box that already changed. If you have application-layer logs, search for requests to pages that were never in your sitemap. A new endpoint that answers with a short string or an upload form is a gift. Disable it, then ask how it got there.
Shrink the blast radius. PeopleSoft does not need to be a global login page. Keep it behind SSO and a network allowlist of the offices and campuses that use it. Turn off anonymous service operations nobody can explain. Rotate database, file-transfer, and API credentials the application uses, because a shell running as the app user already had them.
Write incident response as host compromise. Keep the shell and the logs. Rebuild from known-good media. Burn every integration token. If SharePoint faces the internet in the same environment, run the same hunt for CVE-2026-65660 on that farm before the KEV due date becomes a conversation with counsel.
After the war room, keep the boring controls. Security hardening for these portals means an inventory that includes the ERP, a patch SLA in days for internet-reachable RCE, and threat detection on application and container logs. Practice the web-shell case until someone can name who runs file integrity at 2 a.m. Defense in depth starts on that host, with the same seriousness you already give the identity provider.
Sources
- Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
- SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
