# Attackers evade firewall rules to exploit Oracle PeopleSoft flaw

_Published Saturday, September 26, 2026 at 11:07 AM EDT · Security · Latest · Tier 1 — Major_

![Attackers evade firewall rules to exploit Oracle PeopleSoft flaw — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYN2VWIT2g8mQkV0GeZWzYErKcubb0-baI8J__2nmdElucECc7HrLkdPsR1dz93qjMBI5sr_dL8yPWHf2bwWCBXa3YfutHAeJ-70UCSMuJrHhyOB3RO4OkuDjuw7gxRLXUnK-CeK9jZO0uOJRy-N3w-rV7uZ4t1FnFIWNjEsKtSYQINUvPX31mKzV_5Ert/s1700-nu-rw-lo-l85-e365/oracle-flaw.jpg)

Attackers have renewed widespread exploitation of an Oracle PeopleSoft vulnerability by altering requests to evade web application firewall rules, Google's Mandiant said. The campaign has targeted organizations in several sectors, including healthcare, government and higher education, and placed web shells on dozens of systems. A web shell lets an attacker run commands through a compromised server.

The attackers encode one character in the path to PeopleSoft's vulnerable Environment Management Hub. Some firewalls check the literal path before decoding it, while the application decodes the request and routes it to the vulnerable component. Google urged affected organizations to patch CVE-2026-35273 and check for encoded requests and malicious files.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/attackers-bypass-wafs-to-exploit-oracle.html)

---
Canonical: https://techandbusiness.org/newswire/GM1pYA_g3RzIa96e0sCfk8
Published: 2026-09-26T15:07:07.401Z
Story chronology: 2026-09-26T11:46:40.000Z
Retrieved: 2026-09-26T16:54:02.285Z
Publisher: Tech & Business (techandbusiness.org)
