# oracle exploit — X 热门讨论 (2026-09-26 14:02 UTC)

## @TheHackersNews (The Hacker News) · 09-26 11:50 · ♥27 ↻12 💬7 🚨 One URL-encoded character is helping attackers bypass WAF rules protecting Oracle PeopleSoft.

UNC6240/ShinyHunters is exploiting CVE-2026-35273 to deploy web shells on dozens of systems, then using post-exploitation tools including SIDEEYE.

Read: https://t.co/TwEnxkTzfO https://x.com/TheHackersNews/status/2103814442589065365