ShinyHunters Exploits Oracle PeopleSoft CVE-2026-35273 via WAF Bypass
GTIG says UNC6240 (ShinyHunters) is again exploiting PeopleSoft CVE-2026-35273, using /%50SEMHUB/ to slip past WAF rules. Patch, then hunt.
· 5 minDesk · Vulnerability intelligence
Zero-days, proof-of-concept activity, exploit chains, and emergency patch windows.
GTIG says UNC6240 (ShinyHunters) is again exploiting PeopleSoft CVE-2026-35273, using /%50SEMHUB/ to slip past WAF rules. Patch, then hunt.
· 5 minCISA added Zyxel GS1900 flaw CVE-2026-7273 to KEV on 21 Sept. GreyNoise reports a suspected Chinese-speaking actor took data from 996 switches in 48 countries.
· 4 minCISA added SharePoint code injection flaw CVE-2026-65660 to KEV on 25 Sep. Previdian says it was rescored from 6.5 spoofing to 8.8 RCE and saw attack attempts.
· 5 minForged admin tokens for WSO2 API Manager flaw CVE-2026-5430 (CVSS 10.0) hit honeypots 133 days after the fix. CISA's KEV entry describes the wrong bug.
· 5 minAn unauthenticated attacker can run code on F5 BIG-IP APM with one oversized Bearer token — but only when APM is configured as an OAuth Authorization Server.
· 6 minCVE-2026-86950, a CoreGraphics out-of-bounds write hit via a crafted file, was exploited on iOS before 27. Update to iOS 26.7.1, macOS 26.7.1 or 15.8.1.
· 5 minA WordPress core path traversal, CVE-2026-87902, can reach RCE through pearcmd.php. Probes began the day the fix shipped and CISA lists it as exploited.
· 7 minAttackers exploited Check Point CVE-2026-93616 for root on management servers from 23 July; the fix came 22 September, alongside gateway VPN bug CVE-2026-85102.
· 6 min