September 27, 2026 is shaping up to be one of the most consequential patch days of the year. Across a single news cycle, defenders are confronting six critical vulnerabilities spanning enterprise ERP systems, collaboration platforms, network infrastructure, secure file transfer, content management, and webmail — with confirmed active exploitation across all of them. The breadth of this wave is not coincidental. Threat actors, including groups linked to ShinyHunters, are clearly scanning opportunistically and pivoting quickly across exposed attack surface. If your organization runs any of the affected technologies, treat this briefing as an urgent call to action.

Oracle PeopleSoft and the WAF Bypass Problem

The most alarming item today is the mass exploitation of CVE-2026-35273, a critical flaw in Oracle PeopleSoft carrying a CVSS score of 9.8. Google's threat intelligence teams are tracking a campaign — attributed to ShinyHunters-linked actors — that is actively weaponizing this vulnerability across multiple sectors globally. What makes this particularly dangerous is the reported technique of bypassing Web Application Firewalls to reach the vulnerable endpoint and deploy web shells. Web shells give attackers persistent, interactive access to a compromised server long after the initial intrusion, making detection and remediation significantly harder. Organizations relying solely on perimeter WAF controls for PeopleSoft protection should consider that layer already defeated until the underlying flaw is patched. Audit your PeopleSoft-facing servers immediately for unexpected files in web-accessible directories, unusual outbound connections, and new administrative accounts.

SharePoint Code Injection and MikroTik RouterOS Under Active Attack

CISA added two vulnerabilities to its Known Exploited Vulnerabilities catalog this week: CVE-2026-65660, a code injection flaw in Microsoft SharePoint, and CVE-2026-67279, an improper enforcement of behavioral workflow vulnerability in MikroTik RouterOS. SharePoint is a high-value target because it sits at the center of enterprise document management and internal collaboration — a foothold there can expose sensitive data and serve as a pivot point into broader Active Directory environments. MikroTik routers are widely deployed in SMB and ISP environments and have historically been recruited into botnets and used as covert proxy infrastructure. Both vulnerabilities being in the KEV catalog means federal agencies have mandatory remediation deadlines, but every organization should treat KEV additions as a strong signal of real-world risk regardless of sector.

Kiteworks Zero-Day: When the Vendor Tells You to Shut Down

Kiteworks, a platform used specifically for secure and compliant file sharing, has taken the extraordinary step of advising customers to implement a six-hour server shutdown window to address a potential zero-day vulnerability. When a security-focused vendor recommends taking their own product offline, that guidance must be followed without delay. Secure file transfer platforms are prime targets because they routinely handle regulated, sensitive, and high-value data. If your organization uses Kiteworks, coordinate the maintenance window immediately, review transfer logs for anomalous activity in the preceding weeks, and verify the integrity of files shared through the platform during that period.

WordPress Core Remote File Inclusion and Roundcube Pre-Auth SQL Injection

Two more vulnerabilities round out today's threat landscape. CVE-2026-87902 is a Remote File Inclusion vulnerability in WordPress Core, now added to the CISA KEV catalog. RFI flaws allow attackers to load and execute malicious code hosted remotely, often leading to full server compromise. Given WordPress's enormous install base, this vulnerability will be exploited at scale by automated scanning tools. CVE-2026-48842 is a pre-authentication SQL injection flaw in Roundcube Webmail, affecting versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1, located in the virtuser_query plugin. Pre-auth means no credentials are required to begin exploitation — any internet-exposed Roundcube instance is at risk. SQL injection in a webmail platform can expose the entire mailbox database, credentials, and sensitive communications.

Defensive Priorities

Given the volume and severity of today's disclosures, here is a prioritized action list for security teams:

- Patch Oracle PeopleSoft immediately for CVE-2026-35273 and conduct a web shell hunt on all PeopleSoft-facing servers using file integrity monitoring and endpoint detection tools.
- Apply Microsoft's patch for CVE-2026-65660 in SharePoint and review SharePoint audit logs for unusual page or list modifications and privilege escalation attempts.
- Update MikroTik RouterOS to the latest stable release addressing CVE-2026-67279, disable unnecessary remote management interfaces, and review router configurations for unauthorized rules or tunnels.
- Follow Kiteworks vendor guidance precisely, implement the recommended maintenance window, and treat any data transited through the platform as potentially exposed pending investigation.
- Update all WordPress Core installations to the patched version addressing CVE-2026-87902, audit installed plugins and themes, and verify file system integrity.
- Upgrade Roundcube Webmail to version 1.6.16 or 1.7.1 immediately. If patching cannot happen within hours, consider taking the instance offline or restricting access to trusted IP ranges.
- Validate that WAF rules are not your only control for any of these systems — defense in depth requires patching at the source.
- Increase logging verbosity and alert thresholds on all affected platforms for the next 30 days, and ensure SOC teams are briefed on indicators of compromise associated with web shell deployment and SQL injection attempts.

The convergence of six critical, actively exploited vulnerabilities in a single day underscores the importance of a mature vulnerability management program with clear SLAs for critical patches. Threat actors do not wait for change management cycles.

This briefing is informational and intended to support situational awareness — always consult official vendor advisories and CISA guidance for authoritative remediation instructions.