The hacking group ShinyHunters has modified its exploit to circumvent web application firewall defenses and re‑target unpatched Oracle PeopleSoft installations, expanding from higher‑education victims to a global pool of SaaS customers across tech, healthcare, and government, according to a September 30, 2026 report from SaasRise. The breach revives CVE‑2026‑35273, a 9.8‑severity remote code execution flaw, and forces enterprises to accelerate patching and reassess cloud‑native security controls. The incident illustrates how a single unpatched component can jeopardize an entire SaaS ecosystem, especially when that component underpins HR, finance, or student‑administration workloads.

ShinyHunters bypassed WAF string‑matching defenses by URL‑encoding the PeopleSoft PSEMHUB path, allowing the group to evade well‑known protective controls. Oracle's critical CVE‑2026‑35273 patch for versions 8.61 and 8.62 remains the only effective mitigation. The campaign now targets SaaS customers across tech, healthcare, transportation, and government sectors. FBI Director Kash Patel confirmed the joint arrest of a suspected ShinyHunters member in the Netherlands.

The report warns that the breach could erode SaaS net‑retention and force accelerated security investments. According to the analysis, the PeopleSoft exploit resurgence is a textbook case of how threat actors weaponize legacy vulnerabilities in modern cloud environments. The URL‑encoding trick demonstrates that even well‑known defensive controls can be rendered ineffective when attackers understand the exact decoding order of the application stack.

The report explains that the continued use of on‑premise‑style modules within SaaS stacks creates a hybrid attack surface that adversaries can exploit with minimal friction. For SaaS operators, the incident underscores the strategic advantage of moving toward AI‑native, cloud‑first architectures that eliminate reliance on dated Java deserialization pathways. Companies that have already refactored their HR and finance back‑ends onto micro‑service platforms with immutable infrastructure can more readily apply patches and roll back compromised components. Those still dependent on monolithic Oracle bundles face a higher operational risk and may see churn as customers demand tighter security SLAs.

Looking ahead, the breach could catalyze a wave of regulatory scrutiny, especially in sectors like healthcare and government where protected health information and classified personnel data were exposed. The report anticipates tighter reporting requirements around patch timelines and more aggressive third‑party risk assessments. SaaS investors will likely reward firms that can prove rapid patch deployment pipelines, integrated WAF rule validation, and zero‑trust identity controls, while penalizing those that continue to rely on legacy stacks without clear remediation roadmaps. The incident also highlights the limits of perimeter‑only defenses; without rapid patch deployment, even sophisticated WAFs can be outmaneuvered. For investors, the pressure now centers on whether SaaS vendors can turn security from a cost center into a differentiation engine that protects both customer trust and long‑term contract value.