Threats & Adversaries · Web App Attack

Huntress Maps Webshells Across Shared Member Accounts

Huntress said attackers are using member accounts on a shared recreation-management platform to plant webshells across three municipal servers, and Dutch police separately arrested 24-year-old Pepijn van der Stap in a ShinyHunters probe tied to CVE-2026-35273. The attack has been active for nine days and moved from noisy probing to repeatable file-upload abuse.

The trick is simple: a normal member signs up, uploads a file the server will execute, and the upload turns into code running on the web server instead of a harmless attachment. Because the platform shares upload handling and storage across tenants, the attacker can use that foothold to browse into other tenants’ folders, probe payment data, and even come back after a server cleanup if isolation is still weak.

For operators of shared web apps, the lasting issue is not one compromised account but a trust model that lets low-privilege uploads cross tenant lines. If tenant boundaries and web execution paths overlap, a member login can become a persistent foothold that outlives a single server rebuild or account lockout.

14 sources · Sep 30

CVE-2026-35273

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Known ransomware campaign use. EPSS 9% (95th percentile).

CISA federal remediation date Jun 15 · date passed

Timeline

Sources

Part of the PlainSec briefing for 2026-09-30

Every edition of this story: Huntress Maps Webshells Across Shared Member Accounts

More from today