// Oracle PeopleSoft
Mass Exploitation Wave Hits Enterprise Platforms: Six Critical CVEs Demand Immediate Action
By NeoShield AI Threat Desk · Published 2026-09-27 · 5 min read
#Oracle PeopleSoft#Microsoft SharePoint#MikroTik RouterOS#Kiteworks#WordPress#Roundcube#CVE-2026-35273#CVE-2026-65660
A coordinated surge of active exploitation is targeting Oracle PeopleSoft, Microsoft SharePoint, MikroTik RouterOS, Kiteworks, WordPress, and Roundcube Webmail simultaneously — security teams must triage and act now.
Oracle PeopleSoft and the WAF Bypass Problem
The most alarming item today is the mass exploitation of CVE-2026-35273, a critical flaw in Oracle PeopleSoft carrying a CVSS score of 9.8. Google's threat intelligence teams are tracking a campaign — attributed to ShinyHunters-linked actors — that is actively weaponizing this vulnerability across multiple sectors globally. What makes this particularly dangerous is the reported technique of bypassing Web Application Firewalls to reach the vulnerable endpoint and deploy web shells. Web shells give attackers persistent, interactive access to a compromised server long after the initial intrusion, making detection and remediation significantly harder. Organizations relying solely on perimeter WAF controls for PeopleSoft protection should consider that layer already defeated until the underlying flaw is patched. Audit your PeopleSoft-facing servers immediately for unexpected files in web-accessible directories, unusual outbound connections, and new administrative accounts.
SharePoint Code Injection and MikroTik RouterOS Under Active Attack
CISA added two vulnerabilities to its Known Exploited Vulnerabilities catalog this week: CVE-2026-65660, a code injection flaw in Microsoft SharePoint, and CVE-2026-67279, an improper enforcement of behavioral workflow vulnerability in MikroTik RouterOS. SharePoint is a high-value target because it sits at the center of enterprise document management and internal collaboration — a foothold there can expose sensitive data and serve as a pivot point into broader Active Directory environments. MikroTik routers are widely deployed in SMB and ISP environments and have historically been recruited into botnets and used as covert proxy infrastructure. Both vulnerabilities being in the KEV catalog means federal agencies have mandatory remediation deadlines, but every organization should treat KEV additions as a strong signal of real-world risk regardless of sector.
Kiteworks Zero-Day: When the Vendor Tells You to Shut Down
Kiteworks, a platform used specifically for secure and compliant file sharing, has taken the extraordinary step of advising customers to implement a six-hour server shutdown window to address a potential zero-day vulnerability. When a security-focused vendor recommends taking their own product offline, that guidance must be followed without delay. Secure file transfer platforms are prime targets because they routinely handle regulated, sensitive, and high-value data. If your organization uses Kiteworks, coordinate the maintenance window immediately, review transfer logs for anomalous activity in the preceding weeks, and verify the integrity of files shared through the platform during that period.
WordPress Core Remote File Inclusion and Roundcube Pre-Auth SQL Injection
Two more vulnerabilities round out today's threat landscape. CVE-2026-87902 is a Remote File Inclusion vulnerability in WordPress Core, now added to the CISA KEV catalog. RFI flaws allow attackers to load and execute malicious code hosted remotely, often leading to full server compromise. Given WordPress's enormous install base, this vulnerability will be exploited at scale by automated scanning tools. CVE-2026-48842 is a pre-authentication SQL injection flaw in Roundcube Webmail, affecting versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1, located in the virtuser_query plugin. Pre-auth means no credentials are required to begin exploitation — any internet-exposed Roundcube instance is at risk. SQL injection in a webmail platform can expose the entire mailbox database, credentials, and sensitive communications.
Defensive Priorities
Given the volume and severity of today's disclosures, here is a prioritized action list for security teams:
- Patch Oracle PeopleSoft immediately for CVE-2026-35273 and conduct a web shell hunt on all PeopleSoft-facing servers using file integrity monitoring and endpoint detection tools.
- Apply Microsoft's patch for CVE-2026-65660 in SharePoint and review SharePoint audit logs for unusual page or list modifications and privilege escalation attempts.
- Update MikroTik RouterOS to the latest stable release addressing CVE-2026-67279, disable unnecessary remote management interfaces, and review router configurations for unauthorized rules or tunnels.
- Follow Kiteworks vendor guidance precisely, implement the recommended maintenance window, and treat any data transited through the platform as potentially exposed pending investigation.
- Update all WordPress Core installations to the patched version addressing CVE-2026-87902, audit installed plugins and themes, and verify file system integrity.
- Upgrade Roundcube Webmail to version 1.6.16 or 1.7.1 immediately. If patching cannot happen within hours, consider taking the instance offline or restricting access to trusted IP ranges.
- Validate that WAF rules are not your only control for any of these systems — defense in depth requires patching at the source.
- Increase logging verbosity and alert thresholds on all affected platforms for the next 30 days, and ensure SOC teams are briefed on indicators of compromise associated with web shell deployment and SQL injection attempts.
The convergence of six critical, actively exploited vulnerabilities in a single day underscores the importance of a mature vulnerability management program with clear SLAs for critical patches. Threat actors do not wait for change management cycles.
This briefing is informational and intended to support situational awareness — always consult official vendor advisories and CISA guidance for authoritative remediation instructions.
Related articles
Zero-Day Storm: FortiMail, NetScaler, AI Model RCE, and a $387M Crypto Heist
October 2 brings a convergence of actively exploited zero-days, AI-era attack surfaces, and a nine-figure crypto theft — here is…
Zero-dayCritical Zero-Days Across Network Infrastructure Demand Immediate Action — October 2026
A wave of critical, actively exploited vulnerabilities is hitting core enterprise infrastructure today, spanning SD-WAN…
Citrix NetScalerZero-Days, State Actors, and AI Lures: Defending Against September 30's Threat Wave
A Citrix NetScaler zero-day, a new Apple out-of-bounds write, AI-powered ClickFix campaigns, and Russian state-sponsored backdoor…
NeoShield Security publishes defensive cybersecurity guides for developers, small teams, SOC learners, and MSPs. AI-assisted content is reviewed for safety, defensive purpose, and practical security value.