Oracle PeopleSoft Sees Renewed Mass Exploitation as Attackers Bypass WAF Protections (CVE-2026-35273)
Scope: Oracle PeopleSoft (Internet-Facing Deployments, Particularly Those Relying on WAF Rules as Primary Protection)
Severity: Red
Google warned this week of a renewed wave of mass exploitation targeting CVE-2026-35273, a critical unauthenticated remote code execution flaw in Oracle PeopleSoft that was first exploited as a zero-day earlier this year against academic institutions. The current campaign, linked to ShinyHunters-affiliated attackers, specifically bypasses web application firewall rules that many organizations put in place as their main defense against this vulnerability, meaning a WAF alone is no longer sufficient protection. Once attackers gain access, they upload a valid, digitally signed but trojanized installer to load a backdoor named SIDEEYE into memory, giving them credential theft from browsers and desktop applications, file and process management, an interactive reverse shell, and reverse proxy capabilities, all communicating out to attacker infrastructure. Mandiant previously notified over 100 organizations globally whose systems matched vulnerable endpoints during the initial zero-day wave, most of them in the United States, and this renewed activity suggests the same vulnerable population, or a similarly exposed one, remains at risk. Organizations running Oracle PeopleSoft must apply Oracle's patch for this vulnerability immediately rather than relying on WAF rules, and should audit their environment for unexpected .jsp files and any signed installer resembling the name Ple64.exe as indicators of compromise.
The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.