The ShinyHunters Oracle PeopleSoft WAF bypass is a reminder that a firewall rule is not the same thing as a fix. According to reporting from BleepingComputer, the extortion gang is using a URL-encoding trick to get around web application firewall (WAF) rules that were meant to mitigate the Oracle PeopleSoft flaw tracked as CVE-2026-35273. The result: attackers have been able to resume widespread exploitation of vulnerable servers.

For organizations that leaned on a WAF rule as their main defense, this is a moment to reassess.

How the URL-encoding trick slips past WAF rules

A WAF sits in front of a web application and inspects incoming requests. Many mitigations for a newly disclosed flaw work by matching a known-bad pattern in a request, such as a particular path or string, and blocking it.

URL encoding is a standard way of representing characters in a web address, for example writing a character as a percent sign followed by a code. Web servers decode these values before processing them. That creates a gap: if the WAF rule looks for the literal pattern but the application understands an encoded version of the same request, the two may interpret the traffic differently. Per the report, that is the kind of difference ShinyHunters is exploiting to slip past PeopleSoft-focused WAF rules.

The source article does not publish full technical details of the encoded requests, and we will not speculate beyond what has been reported. What matters for defenders is the principle. A signature-based block on one form of a malicious request can often be sidestepped by presenting that request in a different but equivalent form.

Third-party researchers tracking the campaign have described unauthenticated remote code execution in Oracle PeopleSoft PeopleTools and web shell deployment on unpatched systems. Mandiant and Google Threat Intelligence Group have also been cited as identifying the renewed exploitation. If those descriptions hold, a successful request does not just leak a record; it can give an attacker a foothold on the server.

Why a WAF is a stopgap, not a patch for CVE-2026-35273

WAF rules are often called virtual patches, and they have a real role. When a vendor fix is not yet available or cannot be deployed immediately, a rule can reduce exposure while teams prepare a proper update.

But a virtual patch protects the doorway, not the room behind it. The vulnerable code is still present on the server. Anyone who finds a request format the WAF does not recognize can reach it. That is exactly the situation described here.

A real patch changes the vulnerable behavior itself, so it does not depend on how a request is written or encoded. That is why the guidance in cases like this is consistent: apply the vendor's fix, and treat any WAF rule as a temporary measure that buys time rather than closes the issue.

There is also a process lesson. If your risk register lists a vulnerability as "mitigated" because a WAF rule exists, that status may be overstated. Consider marking such items as "compensating control in place, patch pending" so they stay visible until the fix is applied.

What ShinyHunters' extortion model means for exposed organizations

ShinyHunters is known as an extortion gang, which shapes the risk. The goal is typically to obtain sensitive data or access, then pressure the victim to pay. PeopleSoft often supports human resources, payroll and student systems, which hold exactly the kind of records that give extortionists leverage.

The group's earlier activity offers a picture of how this plays out. In the Udemy data breach linked to ShinyHunters, the group claimed responsibility for a breach of the online learning platform, illustrating a pattern of going after organizations that hold large volumes of user data.

The practical implication is that exposure is not limited to the moment of intrusion. Even after a server is cleaned up, stolen data can be used for pressure, and a web shell left behind can allow re-entry. Organizations running internet-facing PeopleSoft should think in terms of both prevention and compromise assessment.

What This Means For You

If you run Oracle PeopleSoft, particularly with internet-facing components, the key point is simple: do not assume your WAF has you covered for CVE-2026-35273. Attackers have shown they can work around those rules.

If you are a student, employee or customer of an organization that uses PeopleSoft, you cannot patch the server yourself, but you can limit the fallout if data is exposed. Be alert to unexpected emails or messages that reference your account, since extortion campaigns often lead to phishing. Use unique passwords and enable multi-factor authentication where offered. The State of Ransomware 2026 findings are a useful reminder that stolen logins and phishing remain leading ways attackers get in, so account hygiene still matters even when the initial breach is not your fault.

Practical steps: patching, layered defenses and monitoring

For IT and security teams, a sensible order of operations looks like this:

  • Patch first. Apply Oracle's fix for CVE-2026-35273 to every affected PeopleSoft instance as quickly as your change process allows.
  • Keep the WAF, but do not rely on it. Update rules where you can, and consider normalizing or decoding requests before inspection, but treat this as a supporting layer.
  • Reduce exposure. Restrict access to PeopleSoft so that only the components that truly need internet access have it.
  • Hunt for signs of compromise. Because web shells have been reported on unpatched systems, review servers for unexpected files, unusual processes and odd outbound connections, especially if you were unpatched at any point.
  • Monitor and log. Keep detailed web and server logs so you can investigate after the fact.
  • Prepare an incident plan. Know who decides, who communicates and how you would respond to an extortion demand.

The bottom line

The ShinyHunters Oracle PeopleSoft WAF bypass shows how quickly a stopgap can fail when attackers are motivated. Patch PeopleSoft promptly, treat your WAF as one layer among several, and check for signs of compromise on anything that was exposed. For a look at the group's track record, read our coverage of the ShinyHunters Udemy breach, and for broader context on how attackers get into networks, see the ransomware 2026 report linked above.