Critical RCE in Oracle PeopleSoft (CVE-2026-35273) Exploited via WAF Bypass
What It Is — Oracle PeopleSoft contains a critical unauthenticated remote code execution flaw (CVE‑2026‑35273) with a CVSS 9.8 score. Attackers are bypassing web‑application firewalls to deliver web shells.
Exploitability — Public exploit code is circulating; Google reports active, mass exploitation across multiple sectors.
Affected Products — Oracle PeopleSoft (on‑premise and cloud deployments).
Why It Matters for Trust & Control Assurance —
- Demonstrates the need for continuous verification that perimeter controls (WAFs) are correctly configured and effective.
- Highlights the importance of rapid patch management and evidence of remediation to satisfy audit requirements.
- Provides a concrete control‑objective test for vulnerability management that maps to many frameworks (e.g., NIST CSF Identify‑Protect).
Recommended Actions —
- Apply Oracle’s security patch for CVE‑2026‑35273 immediately.
- Review and harden WAF rule sets; test bypass scenarios regularly.
- Update your vulnerability‑management controls and capture remediation evidence in your Trust Center.
Source: The Hacker News