ShinyHunters Bypass WAF Rules to Resume Oracle PeopleSoft Attacks. The ShinyHunters-linked threat actor UNC6240 is actively exploiting CVE-2026-35273 in Oracle PeopleSoft by URL-encoding characters in requests to the PSEMHUB endpoint, defeating WAF rules that previously blocked the attack path. Victims across higher education, technology, healthcare, and government have had web shells (x.jsp, u.jsp), the SIDEEYE backdoor, MeshAgent, and Ple64.exe deployed on their systems.
CISA Adds SharePoint, WSO2, Adobe Commerce, and MikroTik to KEV Catalog. CISA added four actively exploited vulnerabilities this week: CVE-2026-65660 (Microsoft SharePoint code injection enabling RCE), CVE-2026-5430 (WSO2 API Manager path traversal), CVE-2026-71362 (Adobe Commerce/Magento authorization bypass), and CVE-2026-67279 (MikroTik RouterOS pre-auth bypass). Federal agencies face a September 27 patch deadline for the WSO2 and Adobe flaws, with MikroTik and SharePoint deadlines close behind.
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited. CVE-2026-48842, a pre-authentication SQL injection in Roundcube Webmail's virtuser_query plugin, is being actively weaponized against more than 523,000 exposed instances. Patched in May 2026, the flaw allows unauthenticated attackers to exfiltrate mail credentials and messages without any user interaction. Learn more
Elementor WordPress Plugin CSRF Flaw Enables Admin Account Creation. A CSRF flaw in Elementor versions 4.3.0 and 4.3.1 (CVSS 8.8) allows unauthenticated attackers to create rogue administrator accounts by tricking any logged-in admin into clicking a crafted link. The fix is available in version 4.3.2, and sites running the affected versions should treat this as urgent given Elementor's massive installed base.
Key Takeaway
Treat WAF coverage as a detection layer, not a patch substitute: this week demonstrated that URL-encoding and encoding tricks can trivially bypass WAF rules protecting known-vulnerable endpoints.
