Security News Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells TheHackerNews Daniel Bender 26 Sep 2026 Share ShinyHunters-linked attackers exploit CVE-2026-35273 in Oracle PeopleSoft, bypassing WAF rules to deploy web shells on dozens of systems.